Privacy Policy
DRISHTI-PQC is an internal security-posture platform operated by the Cyber & Information Security Division (CISD) of Punjab National Bank. This policy explains what information the platform holds, why it is held, how it is protected, and the choices available to authorised users. It is written to be read in plain language - where a term needs precision, we say so directly.
01 Scope of this policy
This policy governs the DRISHTI-PQC application, its supporting database, and the scanning services it operates. It covers two kinds of data: information about the authorised users who sign in, and technical information about the assets those users choose to scan. It does not govern the bank's other systems, which are subject to their own policies.
DRISHTI-PQC is an internal tool. Access is restricted to personnel provisioned by a CISD administrator. It is not a public service and is not intended for use by the general public or for processing personal data of the bank's customers.
02 Information we hold
The platform holds only what it needs to operate securely:
Account information
- User ID - the credential you sign in with.
- Display name - optional; shown in the header and across the product so teammates recognise you. You control this and may leave it blank.
- Profile photo - optional; if you upload one it is stored as a small, resized image on your account record. You may remove it at any time.
- Password - stored only as a salted one-way hash. The platform never stores or can recover your actual password.
- Multi-factor authentication secret - if you enable MFA, the shared secret used to verify your one-time codes, held encrypted at rest.
- Role - whether your account is an administrator or a member.
Security & audit information
- Sign-in successes and failures, including the source IP address, retained for account-lockout enforcement and security auditing.
- Administrative actions - for example creating a user, resetting a password, or changing a role - recorded in an audit trail.
03 How information is used
Information is used strictly to run the platform and keep it secure. Specifically:
- To authenticate you and maintain your signed-in session.
- To enforce protective controls such as rate-limiting and account lockout after repeated failed sign-ins, in line with recognised security guidance.
- To display your identity to you and to teammates within the platform.
- To maintain an audit trail so security-relevant actions can be reviewed.
- To perform the asset scans you request and to store their results for you.
04 Scan & asset data
When you add an asset - a hostname or IP address - the platform performs a technical assessment and stores the result so you do not have to rescan. This includes the asset's hostname and resolved IP addresses, its TLS configuration and certificate grade, post-quantum readiness indicators, detected findings, and the time of the most recent scan.
This data is technical and infrastructure-oriented. You are responsible for scanning only assets you are authorised to assess. The platform is designed for the bank's own estate and for external endpoints you have a legitimate reason to evaluate.
05 Basis for processing
Processing is carried out in the bank's legitimate interest in securing its own information systems, and in support of its regulatory obligations relating to cyber resilience. Because the platform is an internal tool used by provisioned staff in the course of their duties, the data it holds is operational rather than customer personal data.
06 Retention periods
- Account records are kept while the account is active. When an account is removed, its record is deleted.
- Scan results persist until you or an administrator delete them, or until the parent bank workspace is removed - which deletes every asset within it.
- Audit and sign-in records are retained for as long as needed for security review and to meet the bank's record-keeping requirements.
07 How we protect data
Security is the point of this platform, so its own defences are treated seriously:
- Passwords are stored only as salted one-way hashes and are never recoverable.
- Sessions are carried in signed, HTTP-only cookies that resist tampering and are not readable by page scripts.
- Optional multi-factor authentication adds a time-based one-time code at sign-in.
- Repeated failed sign-ins trigger a temporary lockout to blunt guessing attacks.
- Access is role-based; administrative functions are restricted to administrators.
- Data in transit is protected by encryption between your browser and the platform.
No system is perfectly secure, but the platform is built and maintained to reduce risk to a level appropriate for an internal security tool, and is reviewed by the CISD-DR Innovation Team.
08 Disclosure & sharing
Information held in DRISHTI-PQC is not shared outside the bank. Within the bank, it may be visible to authorised CISD personnel and administrators in the course of operating and auditing the platform. Disclosure beyond this occurs only where the bank is required to do so by law, regulation, or a lawful request from a competent authority.
09 Third-party services
The platform runs on infrastructure and a managed database provided by service providers engaged by the bank. These providers process data only to host the platform and act under the bank's instructions. They are not permitted to use platform data for their own purposes. Scanning activity may reach the external endpoints you choose to assess; those endpoints are outside the bank's control and are governed by their own operators.
10 Your rights & choices
As an authorised user you can:
- Set, change, or remove your display name and profile photo from your profile page.
- Change your own password at any time, and set a new one when first provisioned.
- Enable or manage multi-factor authentication on your account.
- Ask a CISD administrator about the information held on your account, or request its correction or the closure of your account.
11 Sessions & cookies
The platform uses a single, strictly-necessary session cookie to keep you signed in after you authenticate. It is signed, HTTP-only, and used solely to maintain your session. A small amount of information - such as your light or dark theme preference - may be stored locally in your browser for your convenience. The platform does not use tracking or advertising cookies.
12 Changes to this policy
This policy may be updated as the platform evolves or as the bank's requirements change. The effective date at the top reflects the current version. Material changes will be communicated to authorised users through the platform or the usual internal channels.
13 Contact
Questions about this policy or about the information the platform holds should be directed to the Cyber & Information Security Division. Administrators of the platform can route your query to the right team within CISD.