Legal
Information Security Policy
The overarching security principles and practices applicable to the Invincible Intelligence ecosystem, covering governance, access, encryption, incident response, and the security responsibilities shared with our customers.
Effective 01 April 2025 · Last updated 01 August 2026
- Policy Owner
- Chief Information Security Officer (CISO)
1. Purpose
Invincible Intelligence and the companies operating products within the Invincible ecosystem are committed to maintaining appropriate safeguards for the confidentiality, integrity, and availability of information, technology infrastructure, customer data, and business systems.
This Information Security Policy establishes the overarching security principles and practices applicable to the Invincible Intelligence ecosystem.
The objectives of this Policy are to:
- Protect information against unauthorised access, disclosure, alteration, misuse, or destruction;
- Protect customer and enterprise environments;
- Reduce cybersecurity and operational risks;
- Maintain appropriate security controls across our technology products;
- Establish accountability for information security;
- Maintain appropriate incident detection and response capabilities;
- Protect intellectual property and confidential information;
- Support applicable contractual, privacy, cybersecurity, and regulatory obligations; and
- Continually improve the organisation’s information security posture.
2. Invincible Intelligence and Applicable Legal Entities
Invincible Intelligence is currently a common technology brand, website, and product ecosystem and does not itself represent a separately incorporated holding company unless expressly stated otherwise.
Products showcased under Invincible Intelligence may be owned, operated, licensed, or provided by different legal entities, including:
India
- Invincible Ocean Private Limited
- Roboi Private Limited
United Arab Emirates
- Robo Intelligence Information Technology LLC
The legal entity responsible for a particular customer engagement is determined by the applicable agreement, invoice, Statement of Work (“SOW”), order form, or other contractual documentation.
3. Scope
This Policy applies, as appropriate, to:
- Employees
- Directors
- Consultants
- Contractors
- Interns
- Temporary personnel
- Authorised third-party service providers
- Technology partners with access to protected information
It covers information and systems associated with products and platforms displayed through the Invincible Intelligence ecosystem, including:
- Roboi
- Cloudtuner
- MotoIntel
- Finii
- Invincible Intelligence website
- Associated dashboards
- APIs
- Cloud infrastructure
- Edge infrastructure
- On-premises deployments
- AI and Machine Learning systems
- Internal business systems
Product-specific security requirements may supplement this Policy.
4. Information Security Principles
Our information security programme is based upon three fundamental objectives:
Confidentiality
Information should only be accessible to persons, systems, and organisations appropriately authorised to access it.
Integrity
Information and systems should be protected against unauthorised or unintended modification, corruption, or destruction.
Availability
Information and systems should remain reasonably accessible to authorised users when required, subject to applicable service commitments and circumstances beyond reasonable control.
Additional security principles include:
- Least Privilege
- Need-to-Know Access
- Defence in Depth
- Secure by Design
- Privacy by Design
- Zero Trust principles where appropriate
- Segregation of Duties
- Continuous Monitoring
- Risk-Based Security
- Continuous Improvement
5. Security Governance
Information security is treated as an organisational responsibility rather than solely an IT responsibility.
The Company’s information security programme is overseen by management together with the designated Chief Information Security Officer (CISO).
The CISO is responsible, as appropriate, for:
- Security governance;
- Security policies and standards;
- Information security risk management;
- Security awareness;
- Incident coordination;
- Security reviews;
- Vulnerability management oversight;
- Access-control governance;
- Customer security requirements; and
- Continuous improvement of security practices.
- Chief Information Security Officer
- Mr. Sandeep — ciso@invincibleocean.com
Security-related concerns and suspected vulnerabilities may also be reported through the applicable product support channels.
6. Security Framework
The Invincible Intelligence ecosystem follows a risk-based approach to information security.
Our security programme may take guidance from recognised cybersecurity and information security frameworks and industry practices, including, where appropriate:
- ISO/IEC 27001 principles;
- NIST Cybersecurity Framework;
- Secure Software Development practices;
- Cloud-provider security best practices; and
- Applicable cybersecurity and privacy requirements.
Reference to a framework or standard does not constitute a representation that a particular Invincible entity or product is certified under that framework, unless such certification is expressly confirmed by the relevant entity.
7. Risk Management
Information security risks may be periodically identified and assessed based on factors including:
- Nature and sensitivity of information;
- Threat likelihood;
- Potential business impact;
- Infrastructure exposure;
- Vulnerabilities;
- Customer requirements;
- Regulatory requirements;
- Third-party dependencies;
- AI-related risks;
- Cloud security risks;
- Insider threats; and
- Operational dependencies.
Security controls are selected and prioritised based on the assessed risk.
8. Information Classification
Information may be classified according to its sensitivity and business importance.
Classification levels may include:
- Public
- Information approved for public disclosure.
- Internal
- Information intended primarily for authorised personnel.
- Confidential
- Sensitive business, customer, technical, financial, contractual, or operational information.
- Restricted
- Highly sensitive information requiring enhanced access controls.
Personnel are expected to handle information according to its classification.
9. Identity and Access Management
Access to systems and information is granted based on legitimate business requirements.
Security practices may include:
- Role-Based Access Control (RBAC);
- Least-privilege access;
- Multi-Factor Authentication (MFA), where supported and appropriate;
- Strong authentication requirements;
- Unique user accounts;
- Privileged-access restrictions;
- Access logging;
- Periodic access reviews; and
- Removal or modification of access following role changes or termination.
Shared credentials should be avoided wherever technically practical.
10. Privileged Access
Administrative and privileged access is restricted to authorised personnel.
Privileged users are expected to:
- Use administrative access only where required;
- Protect privileged credentials;
- Avoid credential sharing;
- Follow applicable change-management procedures; and
- Maintain appropriate confidentiality.
Where technically available and appropriate, privileged activity may be logged and monitored.
11. Encryption and Data Protection
Appropriate technical safeguards may be implemented depending on the product, customer environment, deployment architecture, and sensitivity of information.
These may include:
- Encryption in transit;
- Encryption at rest;
- TLS or equivalent secure communication protocols;
- Secure credential storage;
- Key-management practices;
- Access controls;
- Network isolation; and
- Data minimisation.
Encryption and security architecture may vary for cloud, edge, and customer-controlled on-premises deployments.
12. Cloud Security
Invincible products may operate across cloud environments including AWS, Microsoft Azure, and other approved infrastructure.
Cloud security measures may include:
- Identity and access management;
- Security groups and network controls;
- Encryption;
- Infrastructure monitoring;
- Logging;
- Vulnerability management;
- Secure configurations;
- Backup procedures;
- Cloud-security posture monitoring; and
- Environment segregation.
Production and development environments should be appropriately segregated wherever practical.
13. Roboi Security Architecture
Roboi is an Edge AI and Video Analytics platform that may process CCTV/video streams to generate analytics, alerts, events, and operational intelligence.
Depending upon the agreed architecture, processing may occur:
- At the edge;
- Within cloud infrastructure;
- Within customer infrastructure;
- On-premises; or
- Through an air-gapped environment.
India
For applicable cloud-hosted Indian deployments, Roboi customer platform data may be hosted in the AWS Mumbai region.
Dashboard: https://dashboard.roboi.ai
UAE
For applicable UAE cloud-hosted deployments, Roboi customer platform data may be hosted within the Microsoft Azure UAE region.
Dashboard: https://dashboard.roboi.ae
On-Premises Deployments
Where Roboi is deployed completely on-premises or in an air-gapped architecture, customer video streams, AI processing, analytics, storage, dashboards, and related information may remain within customer-controlled infrastructure, depending upon the agreed architecture.
Roboi’s security architecture may therefore vary according to customer requirements and deployment models.
14. Video and CCTV Security
Where Roboi processes CCTV or video information:
- Access should be restricted to authorised personnel;
- Video information should only be processed for authorised purposes;
- Customer-configured retention requirements may apply;
- Appropriate technical safeguards should be maintained; and
- Customers remain responsible for ensuring that their CCTV collection and use complies with applicable laws unless otherwise contractually agreed.
Roboi does not independently determine the legality of a customer’s placement or operation of CCTV cameras.
15. Cloudtuner Security
Cloudtuner provides AI-assisted FinOps, SecOps, Cloud Governance, Cloud Security, infrastructure analysis, and managed cloud-security services.
Depending upon customer authorisation, Cloudtuner may analyse:
- Infrastructure metadata;
- Cloud configurations;
- IAM configurations;
- Security events;
- Audit logs;
- Resource utilisation;
- Billing information;
- Network configurations;
- Security alerts; and
- Vulnerability information.
Access to customer cloud environments should follow least-privilege principles wherever technically practical.
Cloudtuner personnel should only access customer environments within the scope authorised by the customer or applicable contract.
16. MotoIntel Security
MotoIntel primarily processes automotive, market intelligence, historical, aggregated, and statistical information.
Its core analytics may include:
- Make, Model and Variant analytics;
- Vehicle registration trends;
- Regional/RTO-level trends;
- Automotive market intelligence;
- Historical datasets; and
- AI-generated forecasts.
MotoIntel’s core automotive analytics platform is not designed around personally identifiable vehicle-owner information.
Information submitted separately through contact forms, enterprise accounts, or business communications remains subject to applicable security and privacy controls.
17. Finii Security
Finii is an enterprise-focused Financial Intelligence, onboarding, and challan-related platform.
Because financial intelligence and onboarding workflows may involve more sensitive information, appropriate security controls may include:
- Role-based access;
- Authentication controls;
- API authentication;
- Encryption;
- Logging;
- Audit trails;
- Consent management;
- Purpose limitation;
- Restricted enterprise access; and
- Data minimisation.
Where information is received through authorised APIs, including ULIP or other permitted sources, access and processing must comply with applicable contractual, consent, regulatory, and API-provider requirements.
18. API Security
APIs operated within the Invincible ecosystem should implement appropriate controls based on risk, which may include:
- Authentication;
- Authorisation;
- API keys or tokens;
- Credential rotation;
- Rate limiting;
- Input validation;
- Logging;
- Access monitoring;
- Network restrictions where applicable; and
- Encryption in transit.
API credentials must be treated as confidential information.
Customers are responsible for protecting credentials issued to them.
19. Secure Software Development
Products developed within the Invincible ecosystem should follow reasonable secure development practices.
Depending upon the system and development lifecycle, these may include:
- Secure architecture reviews;
- Code reviews;
- Source-code access controls;
- Version control;
- Dependency management;
- Secrets management;
- Testing;
- Vulnerability scanning;
- Change management;
- Pre-production validation; and
- Security remediation.
Security requirements should be considered throughout the software-development lifecycle.
20. Vulnerability Management
The Company maintains processes intended to identify, evaluate, prioritise, and remediate vulnerabilities.
These processes may include:
- Vulnerability scanning;
- Dependency reviews;
- Security assessments;
- Patch management;
- Configuration reviews;
- Penetration testing where appropriate; and
- Risk-based remediation.
Remediation priority may depend on severity, exploitability, exposure, affected information, operational impact, and availability of a fix.
21. Security Logging and Monitoring
Systems may maintain logs appropriate to their function, including:
- Authentication events;
- Administrative actions;
- API activity;
- Infrastructure events;
- Security alerts;
- System errors;
- Configuration changes;
- Access activity; and
- Relevant audit events.
Logging and retention periods may differ by product, customer contract, infrastructure, and regulatory requirement.
22. Artificial Intelligence Security
AI and Machine Learning are used across various products within the Invincible Intelligence ecosystem.
AI systems may assist with:
- Anomaly detection;
- Video analytics;
- Threat detection;
- Cloud-security analysis;
- Forecasting;
- Cost optimisation;
- Financial intelligence;
- Pattern recognition;
- Alert prioritisation; and
- Operational analytics.
AI-generated results are probabilistic and may produce false positives, false negatives, incomplete results, or incorrect recommendations.
AI outputs should therefore be treated as decision-support information rather than an absolute security determination.
For significant security, financial, compliance, or infrastructure decisions, appropriate human review is recommended.
23. Customer Data and AI
Confidential identifiable customer information will not intentionally be used to train publicly available general-purpose AI models unless expressly disclosed and appropriately authorised.
Where third-party AI technologies are used, appropriate consideration should be given to:
- Data sensitivity;
- Contractual restrictions;
- Customer requirements;
- Security;
- Privacy;
- Data residency; and
- Applicable laws.
Anonymised or aggregated information may be used to improve systems where permitted by applicable law and contractual arrangements.
24. Endpoint and Workforce Security
Company-managed endpoints may be subject to appropriate safeguards, including:
- Authentication;
- Device security;
- Anti-malware or endpoint protection;
- Security updates;
- Screen locking;
- Restricted administrative privileges;
- Encryption where appropriate; and
- Remote-access controls.
Employees and contractors are responsible for protecting Company systems and credentials assigned to them.
25. Remote Access
Remote access to sensitive systems should be appropriately controlled.
Depending on the system, controls may include:
- VPN or secure connectivity;
- MFA;
- Restricted network access;
- Identity-based controls;
- Device controls; and
- Logging.
Production access should be limited to authorised personnel with legitimate business requirements.
26. Third-Party and Vendor Security
Third-party providers may be used for:
- Cloud hosting;
- Infrastructure;
- Communications;
- Payments;
- Logistics;
- Security;
- Software development;
- Monitoring; and
- Business operations.
Security and privacy considerations should be evaluated when engaging material third-party providers.
Where appropriate, contractual confidentiality, privacy, and security obligations may be established.
However, no organisation can completely eliminate risks arising from third-party infrastructure or service providers.
27. Employee Security and Confidentiality
Employees and authorised personnel with access to sensitive information are expected to:
- Maintain confidentiality;
- Protect passwords and credentials;
- Follow security policies;
- Report suspected security incidents;
- Avoid unauthorised data sharing;
- Use information only for legitimate business purposes; and
- Follow applicable customer confidentiality requirements.
Confidentiality obligations may continue after termination of employment or engagement.
28. Security Awareness
The Company promotes security awareness appropriate to employee roles.
Training or awareness activities may address:
- Phishing;
- Password security;
- Social engineering;
- Data protection;
- Secure development;
- Incident reporting;
- Customer confidentiality; and
- Responsible AI usage.
Personnel with elevated access or specialised security responsibilities may receive additional guidance.
29. Incident Response
The Company maintains procedures intended to identify, investigate, contain, remediate, and recover from information security incidents.
Depending on the nature of the incident, response activities may include:
- Detection and reporting;
- Initial assessment;
- Classification and prioritisation;
- Containment;
- Investigation;
- Remediation;
- Recovery;
- Customer or regulatory notification where required; and
- Post-incident review.
Incidents should be escalated to the appropriate security personnel and CISO.
30. Security Incident Notification
Where a confirmed security incident affects customer information, notification will be handled according to:
- Applicable law;
- Contractual requirements;
- Applicable Data Processing Agreements;
- Nature and severity of the incident; and
- Regulatory notification requirements.
The Company will take reasonable steps to investigate confirmed incidents and mitigate identified risks.
31. Backup and Business Continuity
Appropriate backup, resilience, and recovery practices may be implemented according to system criticality and deployment architecture.
These may include:
- Data backups;
- Infrastructure redundancy;
- Recovery procedures;
- Business continuity planning;
- Disaster recovery planning; and
- Periodic restoration testing.
For customer-controlled on-premises deployments, backup and disaster recovery responsibilities may remain with the customer unless otherwise agreed in writing.
32. Data Retention and Secure Disposal
Information should only be retained for as long as required for legitimate business, contractual, security, or legal purposes.
When information is no longer required, reasonable measures should be used to securely delete, destroy, anonymise, or otherwise dispose of it, subject to technical and legal limitations.
Customer-specific retention periods may be defined in the applicable contract or DPA.
33. Physical Security
Where the Company controls physical offices, hardware, or infrastructure, reasonable physical-security measures may be maintained based upon the sensitivity of the environment.
Data centres operated by third-party cloud providers are subject to the physical-security controls maintained by those providers.
34. Customer Responsibilities
Security is a shared responsibility.
Unless expressly assumed by the applicable Invincible entity under a written agreement, customers remain responsible for:
- Protecting their credentials;
- Managing authorised users;
- Configuring appropriate access permissions;
- Maintaining secure endpoints;
- Maintaining their network security;
- Maintaining backups;
- Maintaining business continuity;
- Reviewing AI-generated recommendations;
- Managing CCTV authorisations where applicable;
- Maintaining regulatory compliance;
- Configuring customer-controlled infrastructure securely; and
- Promptly reporting suspected credential compromise.
35. Cybersecurity Disclaimer
The Invincible Intelligence ecosystem is committed to following reasonable and recognised security practices.
However, no technology platform, cybersecurity programme, AI system, cloud service, edge device, or security control can guarantee absolute protection against every cybersecurity threat.
Cybersecurity risks may include:
- Zero-day vulnerabilities;
- Sophisticated cyberattacks;
- Ransomware;
- Malware;
- Credential theft;
- Social engineering;
- Insider threats;
- Supply-chain attacks;
- Cloud-provider failures;
- Customer misconfiguration;
- Third-party vulnerabilities; and
- Previously unknown attack techniques.
The Company does not warrant that its systems or services will be entirely immune from security incidents.
Security services, including Cloudtuner’s SecOps capabilities, are designed to reduce risk and improve detection, visibility, and security posture, but do not constitute a guarantee that every threat, vulnerability, or attack will be identified or prevented.
Nothing in this section limits liability that cannot lawfully be limited or excluded.
36. Compliance and Continuous Improvement
Information security controls and policies may be periodically reviewed based on:
- Changes in threats;
- Security incidents;
- New products;
- New technologies;
- Customer requirements;
- Regulatory developments;
- Infrastructure changes;
- Security assessments; and
- Industry practices.
Corrective and preventive measures may be implemented where appropriate.
37. Policy Violations
Violation of applicable information security requirements may result in actions including:
- Access restriction;
- Credential revocation;
- Disciplinary action;
- Contract termination; or
- Legal action where appropriate.
The appropriate action will depend on the nature and severity of the violation.
38. Reporting Security Issues
Security concerns, suspected incidents, or vulnerabilities relating to Invincible Intelligence or associated products should be reported promptly.
- Chief Information Security Officer (CISO)
- Mr. Sandeep — ciso@invincibleocean.com
- General Support
- support@invincibleocean.com
- Roboi Support
- support@roboi.ai
- Cloudtuner Support
- support@cloudtuner.ai
Individuals reporting legitimate security concerns are requested not to publicly disclose vulnerability details before the Company has had a reasonable opportunity to investigate and remediate the issue.
39. Policy Review
This Information Security Policy may be reviewed and updated periodically to reflect changes in:
- Corporate structure;
- Products;
- Infrastructure;
- Security threats;
- Technology;
- Applicable laws;
- Customer requirements; and
- Recognised security practices.
The current version may be published through the Invincible Intelligence website.
40. Corporate Clarification
Invincible Intelligence currently represents a common technology brand, website, and product ecosystem and is not itself a separately incorporated holding company unless expressly stated otherwise.
Information-security obligations relating to a particular customer, product, or service are undertaken by the legal entity identified in the applicable agreement, invoice, order form, SOW, DPA, or other contractual documentation.
If the corporate structure changes or a formal holding company is established, this Policy may be updated accordingly.