Punjab National Bank · CISD

Privacy Policy

Applies to: DRISHTI-PQC internal platform Effective: 1 July 2026 Owner: Cyber & Information Security Division

DRISHTI-PQC is an internal security-posture platform operated by the Cyber & Information Security Division (CISD) of Punjab National Bank. This policy explains what information the platform holds, why it is held, how it is protected, and the choices available to authorised users. It is written to be read in plain language - where a term needs precision, we say so directly.

01 Scope of this policy

This policy governs the DRISHTI-PQC application, its supporting database, and the scanning services it operates. It covers two kinds of data: information about the authorised users who sign in, and technical information about the assets those users choose to scan. It does not govern the bank's other systems, which are subject to their own policies.

DRISHTI-PQC is an internal tool. Access is restricted to personnel provisioned by a CISD administrator. It is not a public service and is not intended for use by the general public or for processing personal data of the bank's customers.

02 Information we hold

The platform holds only what it needs to operate securely:

Account information

Security & audit information

03 How information is used

Information is used strictly to run the platform and keep it secure. Specifically:

No advertising, no profiling. Your information is never used for advertising, sold, or used to build a behavioural profile. It exists to run an internal security tool and for nothing else.

04 Scan & asset data

When you add an asset - a hostname or IP address - the platform performs a technical assessment and stores the result so you do not have to rescan. This includes the asset's hostname and resolved IP addresses, its TLS configuration and certificate grade, post-quantum readiness indicators, detected findings, and the time of the most recent scan.

This data is technical and infrastructure-oriented. You are responsible for scanning only assets you are authorised to assess. The platform is designed for the bank's own estate and for external endpoints you have a legitimate reason to evaluate.

Some capabilities that would move data outside the bank's perimeter - for example parsing externally aggregated reports - are held under governance review and are not enabled by default. Where such a feature is introduced, it will be clearly indicated and separately controlled.

06 Retention periods

07 How we protect data

Security is the point of this platform, so its own defences are treated seriously:

No system is perfectly secure, but the platform is built and maintained to reduce risk to a level appropriate for an internal security tool, and is reviewed by the CISD-DR Innovation Team.

08 Disclosure & sharing

Information held in DRISHTI-PQC is not shared outside the bank. Within the bank, it may be visible to authorised CISD personnel and administrators in the course of operating and auditing the platform. Disclosure beyond this occurs only where the bank is required to do so by law, regulation, or a lawful request from a competent authority.

09 Third-party services

The platform runs on infrastructure and a managed database provided by service providers engaged by the bank. These providers process data only to host the platform and act under the bank's instructions. They are not permitted to use platform data for their own purposes. Scanning activity may reach the external endpoints you choose to assess; those endpoints are outside the bank's control and are governed by their own operators.

10 Your rights & choices

As an authorised user you can:

11 Sessions & cookies

The platform uses a single, strictly-necessary session cookie to keep you signed in after you authenticate. It is signed, HTTP-only, and used solely to maintain your session. A small amount of information - such as your light or dark theme preference - may be stored locally in your browser for your convenience. The platform does not use tracking or advertising cookies.

12 Changes to this policy

This policy may be updated as the platform evolves or as the bank's requirements change. The effective date at the top reflects the current version. Material changes will be communicated to authorised users through the platform or the usual internal channels.

13 Contact

Questions about this policy or about the information the platform holds should be directed to the Cyber & Information Security Division. Administrators of the platform can route your query to the right team within CISD.

© Punjab National Bank · Cyber & Information Security Division. DRISHTI-PQC is an internal platform developed in-house by the CISD-DR Innovation Team.
Security evolves. Trust stays. PNB.
Read the Terms & Conditions →