ANTI-FRAUD AND SECURITY POLICY

Effective Date: February 14, 2025
Version: 2.0

1. Fraud Prevention Framework

  • AI-powered transaction monitoring
  • Machine learning risk scoring
  • Real-time fraud detection
  • Manual review protocols
  • Behavioral analytics
  • Identity verification (Aadhaar/PAN)
  • Address verification
  • Phone number OTP
  • Email confirmation
  • Bank account validation
2. Transaction Monitoring
  • Unusual purchase patterns
  • Multiple payment methods
  • Rapid order velocity
  • High-value transactions
  • New account activity
  • Geographic anomalies
  • Transaction blocking
  • Additional verification required
  • Manual review triggered
  • Account temporary hold
  • Law enforcement notification (if required)
3. Seller Fraud Prevention
  • Business verification
  • Director/owner validation
  • Bank account verification
  • GST validation
  • Previous marketplace history
  • Listing quality checks
  • Pricing anomalies
  • Fulfillment rates
  • Customer complaints
  • Return patterns
  • Revenue velocity
4. Buyer Fraud Prevention
  • Strong password requirements
  • Two-factor authentication
  • Login anomaly detection
  • Device fingerprinting
  • Session management
  • PCI-DSS compliance
  • Tokenization
  • 3D Secure authentication
  • CVV verification
  • Velocity checks
5. Data Security Measures
  • 256-bit SSL encryption
  • End-to-end encryption
  • Database encryption
  • API security
  • DDoS protection
  • WAF implementation
  • Role-based access
  • Principle of least privilege
  • Regular access reviews
  • Multi-factor authentication
  • Audit logging
6. Incident Response
  • 24/7 security operations
  • Incident commander
  • Technical team
  • Legal team
  • Communications team
  • Detection and analysis
  • Containment
  • Eradication
  • Recovery
  • Post-incident review
  • Stakeholder notification
7. Compliance Framework
  • Information Technology Act, 2000
  • RBI guidelines
  • PCI-DSS standards
  • ISO 27001 (targeted)
  • GDPR (for EU users)
  • Annual security audits
  • Penetration testing
  • Vulnerability assessments
  • Compliance reviews
  • Third-party audits
8. User Responsibilities
  • Unique strong passwords
  • Never share credentials
  • Regular password updates
  • Secure device usage
  • Logout from shared devices
  • Verify seller credibility
  • Use platform payment only
  • Don’t share financial details
  • Report suspicious activity
  • Keep transaction records
9. Prohibited Activities
  • Fake account creation
  • Account takeover
  • Identity theft
  • Credential stuffing
  • Social engineering
  • Payment fraud
  • Chargeback fraud
  • Refund fraud
  • Coupon/promo abuse
  • Money laundering
  • Counterfeit products
  • Misleading descriptions
  • Phantom inventory
  • Price manipulation
  • Review manipulation
10. Penalties And Enforcement
  • Automated detection
  • Manual investigation
  • Evidence collection
  • User notification
  • Appeal process
  • Warning issued
  • Account suspension
  • Permanent ban
  • Fund freezing
  • Legal action
  • Law enforcement referral
11. Reporting Mechanisms
  • In-app reporting
  • Email: [email protected]
  • Hotline: [Number]
  • Online form
  • Chatbot assistance
  • Anonymous reporting
  • Confidentiality maintained
  • No retaliation policy
  • Reward program
  • Legal protection