Kriqy is operated by Krijyo Growth Solutions, Whitefield, Bengaluru, Karnataka, India.
Employee feedback requires trust.
Kriqy is designed around the principle that organizations should be able to understand employee experiences and act on them without unnecessarily exposing the identity of individuals who were promised anonymity.
This Security & Trust Policy describes the security and privacy principles applicable to Kriqy.
Security questions may be directed to:
1. Our Security Approach
Kriqy uses technical and organizational measures designed to protect the confidentiality, integrity and availability of information processed through the platform.
Our security approach is based on principles including:
- least-privilege access;
- organization-level data isolation;
- role-based authorization;
- employee anonymity protections;
- encryption;
- secure credential management;
- monitoring and logging;
- backups and recovery;
- vulnerability management;
- incident response; and
- data minimization.
Security controls evolve as the platform and threat environment develop.
2. Employee Anonymity
Employee trust is a fundamental design consideration for Kriqy.
Where functionality is expressly presented as anonymous, Kriqy is designed so that authorized customer users cannot use that functionality to identify the individual who submitted an anonymous response.
For applicable aggregated reporting, Kriqy enforces a minimum reporting threshold of five respondents.
Where fewer than the required number of respondents are represented, applicable aggregated results are suppressed or withheld.
These safeguards are designed to reduce the risk of identifying an individual through small-group reporting.
Organizations using Kriqy are prohibited from intentionally attempting to circumvent these protections or re-identify anonymous respondents.
Not every Kriqy feature is anonymous. Where functionality is attributed or requires identity for operational purposes, Kriqy will not describe that functionality as anonymous.
3. Organization Data Isolation
Kriqy is designed as a multi-tenant SaaS platform with controls intended to prevent one customer organization from accessing another customer's information.
Access to customer information is scoped according to organization membership and applicable authorization rules.
Database and application-layer access controls should be maintained and tested as the service evolves to help prevent unauthorized cross-organization access.
4. Role-Based Access
Kriqy uses role-based access controls to restrict functionality and information according to authorized user roles.
Administrative and organizational permissions are designed according to least-privilege principles.
Where employee feedback is subject to anonymity safeguards, authorized customer roles receive aggregated or otherwise permitted information rather than respondent identity through anonymous reporting functionality.
5. Encryption
Kriqy uses encryption mechanisms appropriate to the relevant systems and services to protect information in transit.
Where supported and applicable within Kriqy's production infrastructure, stored customer information is protected using encryption-at-rest capabilities provided by the underlying infrastructure.
Cryptographic keys and credentials must be managed through controlled infrastructure rather than intentionally exposed in client-side source code.
6. Authentication
Access to authenticated Kriqy functionality requires appropriate authentication.
Kriqy maintains controls designed to prevent unauthorized account access.
Users are responsible for maintaining secure credentials and immediately notifying Kriqy or their organization if they believe their account has been compromised.
Additional authentication protections may be introduced or required depending on account type and service configuration.
7. Infrastructure and Secrets
Production credentials, service-role credentials, API keys and other sensitive secrets must be stored through appropriate server-side or secret-management mechanisms.
Sensitive production credentials must not intentionally be exposed through public source code or client-side application bundles.
Access to production infrastructure is limited to personnel and systems requiring such access for legitimate operational purposes.
8. Environment Separation
Kriqy aims to maintain appropriate separation between development, testing/staging and production environments.
Production credentials and secrets should not be reused in development environments unless technically necessary and appropriately protected.
Production customer information should not be copied into development or testing environments by default.
Where production-derived information must exceptionally be used for troubleshooting or testing, appropriate authorization, minimization and protection measures should be applied.
9. Logging and Monitoring
Kriqy maintains logs appropriate for security, reliability, troubleshooting, fraud prevention and legal compliance.
Logs may include authentication activity, system events, administrative activity, errors and security-relevant events.
Access to logs is restricted according to operational need.
Kriqy will maintain logs for periods required by applicable law, including applicable cybersecurity directions issued by Indian authorities.
Logs containing personal data are subject to appropriate security and access restrictions.
10. Backups and Recovery
Kriqy uses backup and recovery mechanisms appropriate to its production infrastructure.
Backup access is restricted.
Recovery procedures should be periodically reviewed or tested as appropriate to verify that critical information can be restored following qualifying failures.
Backup information is retained according to applicable operational and legal requirements and is deleted or overwritten according to the applicable backup lifecycle.
11. Vulnerability Management
Kriqy follows processes designed to identify, assess and remediate security vulnerabilities.
This may include:
- dependency monitoring;
- security updates;
- application testing;
- access-control reviews;
- code review;
- infrastructure review; and
- remediation based on severity and risk.
Security practices will evolve as Kriqy's architecture and customer requirements evolve.
12. Secure Development
Security considerations are incorporated into Kriqy's software-development process.
Changes to production systems should undergo appropriate review and testing before deployment.
Development practices are intended to reduce risks including:
- unauthorized access;
- injection attacks;
- broken authorization;
- secret exposure;
- cross-tenant access;
- insecure dependencies; and
- unintended disclosure of employee information.
Security-sensitive functionality, particularly anonymity and organization-level authorization, should receive additional review.
13. Administrative Access
Access by Kriqy personnel to production systems and customer information is restricted to legitimate operational purposes.
Where administrative access is required, access should follow least-privilege principles and be limited to authorized personnel.
Personnel with access to confidential information are expected to be subject to appropriate confidentiality obligations.
14. Service Providers and Subprocessors
Kriqy may use trusted service providers for infrastructure and operational services.
Before engaging providers that process customer personal data, Kriqy evaluates relevant security and privacy considerations appropriate to the nature of the service.
Where required, providers are subject to contractual privacy, confidentiality and security obligations.
Kriqy may maintain a separate list of material subprocessors as appropriate.
15. Security Incident Response
Kriqy maintains procedures designed to identify, investigate, contain and remediate security incidents.
When a security incident affecting customer information occurs, Kriqy will:
- investigate the incident;
- take reasonable steps to contain it;
- mitigate identified risks;
- preserve appropriate evidence and logs;
- remediate relevant vulnerabilities; and
- provide legally or contractually required notifications.
Kriqy will report qualifying cybersecurity incidents to applicable authorities within timeframes required by Indian law, including applicable CERT-In requirements.
Where Kriqy acts as a processor for a customer, Kriqy will provide incident information to the customer as required by applicable contractual and legal obligations.
16. Data Retention and Secure Deletion
Customer information is retained only as necessary to provide Kriqy and satisfy applicable contractual, security and legal requirements.
When information is no longer required, Kriqy will delete, anonymize or otherwise dispose of it according to applicable retention procedures.
Following customer termination, customer information will be handled according to the applicable agreement and documented retention procedures.
Residual copies may remain temporarily in protected backups until those backups expire or are overwritten.
17. Privacy by Design
Kriqy aims to minimize unnecessary exposure of employee information.
Privacy considerations include:
- collecting only information reasonably required for intended functionality;
- limiting access according to roles;
- suppressing small-group anonymous reporting;
- separating organizations;
- minimizing exposure of identifying information; and
- reviewing new functionality for privacy implications.
18. Customer Security Responsibilities
Security is a shared responsibility.
Customers are responsible for:
- controlling who receives Kriqy accounts;
- promptly removing former or unauthorized users;
- protecting credentials;
- configuring permissions appropriately;
- using secure devices and networks;
- complying with applicable employment and privacy law;
- respecting employee anonymity;
- not attempting to re-identify anonymous respondents; and
- promptly reporting suspected security issues.
19. Responsible Security Reporting
If you believe you have discovered a security vulnerability affecting Kriqy, please report it privately to:
Please include sufficient information for us to understand and investigate the issue.
Do not:
- access information belonging to other users or organizations;
- destroy or modify information;
- disrupt Kriqy services;
- conduct denial-of-service testing;
- use social engineering;
- publicly disclose an unresolved vulnerability; or
- exceed what is reasonably necessary to demonstrate the issue.
We will review legitimate reports and respond as appropriate.
20. Compliance
Kriqy seeks to operate in accordance with applicable privacy, data-protection and cybersecurity requirements.
Depending on the customer and processing activity, relevant requirements may include:
- India's Digital Personal Data Protection framework;
- applicable provisions of India's Information Technology and cybersecurity framework;
- CERT-In cybersecurity requirements;
- the EU General Data Protection Regulation where applicable;
- UK data protection requirements where applicable; and
- applicable U.S. privacy requirements.
References to these laws do not constitute a claim that Kriqy holds a particular certification.
21. No Unsupported Certification Claims
Kriqy will not claim to possess an independent security certification, audit report or compliance attestation unless that certification, report or attestation has actually been obtained and remains applicable.
Any future certifications or independent assessments will be identified separately.
22. Security Is Continuous
No technology platform can guarantee absolute security.
Kriqy continually evaluates its safeguards as the service, customer requirements, applicable laws and security threats evolve.
Customers with security questionnaires, vendor assessments or enterprise security requirements may contact:
23. Contact
Krijyo Growth Solutions Kriqy Whitefield, Bengaluru, Karnataka, India Email: all@kriqy.com
© 2026 Krijyo Growth Solutions. All rights reserved.
