Security & Privacy Policy

EaseMyPrompt.ai — Security & Privacy Policy

Effective Date: August 2026 | Version: 1.0 | EaseMyPrompt.ai, a product of Derek AI Labs

1. Our Security Commitment

EaseMyPrompt.ai, a product of Derek AI Labs treats the security and privacy of user data as a core obligation. We implement industry-standard security measures to protect your personal data against unauthorised access, disclosure, alteration, and destruction, in accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2. Technical Security Measures

2.1 Encryption

• All data in transit is encrypted using TLS 1.2 or higher

• Sensitive data at rest is encrypted using AES-256 or equivalent

• Passwords are hashed using bcrypt with appropriate cost factors

• API keys and secrets are stored in encrypted vaults

2.2 Access Control

• Role-based access control (RBAC) limits internal data access to authorised personnel only

• Multi-factor authentication (MFA) is required for all internal administrative accounts

• Privileged access is logged, monitored, and audited quarterly

• The principle of least privilege applies to all system access

2.3 Infrastructure Security

• Our infrastructure is hosted with reputable cloud providers with ISO 27001 certification

• Regular penetration testing is conducted by independent third parties

• Vulnerability scanning runs continuously on all production systems

• Web Application Firewall (WAF) protects against OWASP Top 10 threats

• DDoS protection is implemented at the network level

3. Organisational Security Measures

• All employees undergo background verification before accessing production systems

• Security awareness training is conducted annually for all staff

• A security incident response plan is maintained and tested annually

• Data access is logged and audited for anomalous activity

4. Data Breach Response

In the event of a personal data breach:

• We will assess the breach within 24 hours of discovery

• Affected users will be notified without undue delay, and within 72 hours where required by law

• We will notify relevant Indian regulatory authorities as required

• We will take immediate steps to contain the breach and prevent recurrence

• A full incident report will be completed within 30 days

5. Third-Party Security

We require all third-party service providers who process personal data on our behalf to:

• Maintain appropriate security standards consistent with SPDI Rules

• Enter into data processing agreements that include security obligations

• Notify us immediately of any security incidents affecting our data

• Permit audits or provide third-party audit certifications upon request

6. Payment Security

Payment card data is never stored on our servers. All payment processing is handled by PCI-DSS compliant third-party payment processors. We store only masked card details (last 4 digits) for reference purposes.

7. Security of AI Systems

We implement specific security measures for our AI components:

• Model inputs and outputs are monitored for anomalous patterns

• Prompt injection attacks are detected and blocked

• AI model access is restricted to authorised service accounts

• Training data and model weights are stored securely with restricted access

8. Reporting Security Issues

To report a security vulnerability, please email legal@easemyprompt.ai with subject line "Security Disclosure". Do not publicly disclose vulnerabilities before we have had a reasonable opportunity to investigate and remediate.