Digital Code SMC (Private) Limited (“Digital Code,” “we,” “us,” or “our”) is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us.
This Information Security Policy describes the principles and safeguards used to protect our website, information systems, business operations, software projects, clients, employees, partners, and service providers in Pakistan and the United Arab Emirates.
1. Company Information
Registered Name: Digital Code SMC (Private) Limited
Country of Registration: Islamic Republic of Pakistan
Official Email: info@digitalcode.pk
Landline: +92 51 8990491
WhatsApp: +92 300 0390491
Pakistan Office: Office 01, 3rd Floor, Plaza 153, Nasir Arcade, Bahria Town Phase 4, Civic Center, Islamabad, Pakistan
UAE Office: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE
Unless expressly stated, the existence of a UAE office or business presence does not mean that Digital Code is incorporated or licensed as a separate legal entity in the UAE.
2. Purpose
The purpose of this Policy is to establish a structured framework for identifying, managing, and reducing information-security risks.
Our security objectives are to:
- Protect confidential and sensitive information from unauthorized access.
- Maintain the accuracy and integrity of information.
- Keep systems and services available to authorized users.
- Protect client projects, software, and intellectual property.
- Prevent, detect, respond to, and recover from security incidents.
- Meet applicable contractual, regulatory, and legal obligations.
- Promote security awareness throughout the organization.
3. Scope
This Policy applies to:
- Directors, employees, interns, and temporary staff
- Independent contractors and consultants
- Third-party service providers and business partners
- Systems, networks, devices, applications, databases, and cloud services
- Source-code repositories and development environments
- Digital Code’s website and communication platforms
- Client information and project materials
- Information processed from Pakistan, the UAE, or another jurisdiction
Third parties with access to Digital Code systems or information may be required to comply with appropriate contractual security and confidentiality obligations.
4. Information Assets
Information assets protected under this Policy include:
- Client, customer, employee, contractor, and partner information
- Software source code and repositories
- Website content, applications, databases, and backups
- Blockchain, Web3, artificial-intelligence, and software innovations
- Product designs, technical documentation, and architecture
- Business plans and digital marketing strategies
- Contracts, proposals, financial records, and invoices
- Authentication credentials, encryption keys, and access tokens
- Communication records and project-management information
- Physical and cloud-based infrastructure
- Intellectual property and confidential business information
5. Security Governance and Responsibilities
5.1 Management
Senior management is responsible for:
- Supporting the information-security program.
- Assigning security responsibilities.
- Providing appropriate resources and oversight.
- Reviewing significant risks and incidents.
- Promoting a security-conscious workplace.
5.2 Employees and Contractors
All personnel must:
- Follow this Policy and related procedures.
- Protect passwords and authentication credentials.
- Access information only for authorized business purposes.
- Keep confidential information secure.
- Complete required security awareness activities.
- Promptly report suspected incidents, vulnerabilities, or data loss.
- Return or securely delete company information when their engagement ends.
5.3 System and Information Owners
Responsible personnel must identify security requirements, approve access, review risks, and ensure that appropriate safeguards are maintained for the systems and information under their control.
6. Risk Management
Digital Code follows a risk-based approach to information security. Security risks may be identified through:
- System and application reviews
- Vulnerability assessments
- Code reviews and security testing
- Incident analysis
- Vendor assessments
- Changes to technology or business operations
- Legal and contractual compliance reviews
Identified risks will be evaluated according to their likelihood and potential impact. Appropriate measures will then be implemented to avoid, reduce, transfer, or formally accept the risk.
7. Information Classification and Handling
Information may be classified according to its sensitivity and business importance:
- Public: Approved for public disclosure.
- Internal: Intended for authorized internal use.
- Confidential: Sensitive business, client, employee, or project information.
- Restricted: Highly sensitive information requiring the strongest access controls.
Personnel must handle, share, store, copy, retain, and dispose of information according to its classification.
Confidential or restricted information must not be transferred through unauthorized personal accounts, public links, or insecure communication channels.
8. Access Control
Access to Digital Code systems and information is governed by the principles of least privilege and legitimate business need.
Security controls may include:
- Unique user accounts
- Role-based access permissions
- Strong password requirements
- Multi-factor authentication
- Account approval procedures
- Periodic access reviews
- Logging and monitoring
- Timely removal of unnecessary access
- Immediate access revocation following termination, where appropriate
Users must not share accounts, passwords, authentication codes, API keys, or other credentials.
Privileged and administrative access will be restricted to specifically authorized individuals and subject to enhanced safeguards.
9. Authentication and Password Security
Users must create strong, unique passwords and protect them against unauthorized disclosure.
Where supported and proportionate to the risk, multi-factor authentication will be enabled for:
- Email and communication platforms
- Cloud services
- Source-code repositories
- Production environments
- Administrative accounts
- Financial and sensitive business systems
Credentials must not be stored in source code, public repositories, unprotected documents, or unsecured communication channels.
10. Encryption and Data Protection
Digital Code uses reasonable technical and organizational safeguards appropriate to the sensitivity of the information.
These safeguards may include:
- Encryption of information during transmission
- Encryption of sensitive information at rest where appropriate
- Secure management of encryption keys and credentials
- Access restrictions
- Data masking or anonymization
- Secure backups
- Approved data-transfer methods
- Logging and monitoring of sensitive systems
Sensitive client or personal information should only be collected and retained when necessary for an authorized business purpose.
11. Secure Software Development
Digital Code integrates security considerations into its software-development lifecycle.
Depending on the project and risk level, controls may include:
- Security requirements during project planning
- Separation of development, testing, and production environments
- Source-code version control
- Peer review and testing
- Input validation and secure authentication
- Dependency and vulnerability management
- Secrets and credential management
- Secure API development
- Controlled production deployment
- Backup and rollback procedures
- Security testing before release
- Timely remediation of identified vulnerabilities
Client-specific requirements may be defined in the relevant agreement, statement of work, or security schedule.
12. Artificial Intelligence and Automated Tools
Where artificial-intelligence tools are used, Digital Code will take reasonable measures to prevent unauthorized disclosure of confidential, personal, or client information.
Personnel must not submit restricted information, production credentials, confidential source code, or personal data to publicly accessible AI systems unless the use has been reviewed and authorized.
AI-generated code and content should be reviewed for security, accuracy, licensing, privacy, and suitability before being used in a production environment.
13. Cloud and Infrastructure Security
Cloud platforms, hosting services, and infrastructure must be selected and configured with regard to:
- Data sensitivity
- Access controls
- Encryption capabilities
- Backup and recovery
- Logging and monitoring
- Geographic data location
- Service availability
- Contractual protection
- Legal and regulatory requirements
Production environments should be logically separated from development and testing environments where reasonably practicable.
14. Endpoint and Network Security
Digital Code applies reasonable security measures to company systems and devices, which may include:
- Supported operating systems and software
- Security updates and patches
- Anti-malware protection
- Device authentication
- Screen locking
- Firewall and network protections
- Restricted administrative privileges
- Secure wireless-network configurations
- Remote-access controls
- Secure device disposal
Lost, stolen, compromised, or unauthorized devices must be reported promptly.
15. Remote Working
Employees and contractors working remotely must:
- Use approved systems and communication channels.
- Protect devices from unauthorized physical access.
- Avoid accessing confidential information through unsecured public networks.
- Use approved secure remote-access tools where required.
- Prevent family members or unauthorized individuals from using business accounts or devices.
- Securely store and dispose of printed information.
16. Physical Security
Reasonable physical safeguards will be applied to offices, workspaces, equipment, and records.
These may include:
- Controlled access to offices and restricted areas
- Visitor supervision
- Protection of equipment and documents
- Secure storage
- Clear-desk and screen-locking practices
- Secure destruction of confidential paper records and storage devices
17. Third-Party and Supplier Security
Before providing a service provider with access to sensitive information or systems, Digital Code may evaluate:
- The nature and sensitivity of the information involved
- The provider’s security practices
- Privacy and data-processing terms
- Confidentiality obligations
- Data-storage and transfer locations
- Incident-notification procedures
- Service continuity and recovery arrangements
- Subcontractor use
Third-party access must be limited to what is necessary and removed when no longer required.
18. Backup, Recovery, and Business Continuity
Digital Code maintains backup and recovery measures appropriate to its systems and contractual obligations.
These measures may include:
- Regular backups of important information
- Protection of backup access
- Geographically or logically separated backup storage
- Restoration testing
- Recovery procedures
- Business-continuity planning
- Alternative communication arrangements
- Identification of critical systems and dependencies
Recovery priorities will be based on business impact, contractual requirements, and system criticality.
19. Vulnerability and Patch Management
Digital Code takes reasonable steps to identify and address security vulnerabilities.
This may include:
- Monitoring security updates
- Applying risk-appropriate patches
- Reviewing third-party dependencies
- Performing security testing
- Investigating reported vulnerabilities
- Prioritizing remediation according to severity and exposure
No individual may conduct unauthorized security testing, scanning, exploitation, or penetration testing against Digital Code systems.
20. Logging and Monitoring
Relevant systems may generate security, access, and operational logs for purposes including:
- Detecting unauthorized activity
- Investigating incidents
- Troubleshooting system problems
- Protecting infrastructure
- Meeting legal or contractual obligations
Monitoring will be proportionate to legitimate security requirements and conducted in accordance with applicable privacy and employment laws.
21. Incident Reporting and Response
Employees, contractors, users, and service providers should promptly report suspected security incidents, including:
- Unauthorized account access
- Lost or stolen devices
- Malware or phishing
- Accidental disclosure
- Data loss
- Exposed credentials
- Website or system compromise
- Suspicious network activity
- Known or suspected personal-data breaches
Digital Code’s response process may include:
- Identifying and recording the incident.
- Containing the threat.
- Assessing affected systems and information.
- Preserving relevant evidence.
- Removing the cause of the incident.
- Restoring affected services.
- Notifying clients, individuals, regulators, or authorities where legally or contractually required.
- Reviewing the incident and implementing corrective measures.
Security incidents should be reported to info@digitalcode.pk with the subject line “Security Incident.”
22. Security Awareness
Personnel may receive security awareness and role-appropriate guidance covering:
- Password and account protection
- Phishing and social-engineering threats
- Safe information handling
- Privacy responsibilities
- Remote-working security
- Incident reporting
- Secure software-development practices
Personnel with privileged or specialized technical responsibilities may receive additional security training.
23. Compliance in Pakistan and the UAE
Digital Code seeks to comply with applicable information-security, electronic-transactions, cybercrime, privacy, intellectual-property, and contractual requirements.
Pakistan
Operations in Pakistan will be managed in accordance with applicable Pakistani laws and regulations, including relevant electronic-transactions and cybercrime requirements.
United Arab Emirates
Where Digital Code processes information or provides services in the UAE, applicable UAE federal and emirate-level requirements will be considered, including relevant requirements concerning:
- Personal-data protection
- Electronic transactions
- Cybercrime
- Confidentiality
- Intellectual property
- Security-incident management
- International data transfers
Separate legal regimes may apply in the Dubai International Financial Centre or Abu Dhabi Global Market.
Specific regulatory or industry requirements will be addressed in the relevant client contract where a project involves healthcare, finance, digital assets, government systems, or other regulated activities.
24. Policy Violations
Violations of this Policy may result in:
- Removal or suspension of access
- Corrective or disciplinary action
- Termination of employment or contract
- Legal action
- Notification to clients, regulators, or law-enforcement authorities where required
Any action taken will be proportionate to the circumstances and consistent with applicable law and contractual obligations.
25. Policy Review and Updates
This Policy will be reviewed periodically and may be updated when there are changes to:
- Business operations
- Security risks
- Technology
- Legal requirements
- Client obligations
- Internal procedures
The current public version will be posted on our Website with its effective date. Material changes will be communicated where required by law or contract.
26. Contact Information
For questions, concerns, vulnerability reports, or security incidents, contact:
Digital Code SMC (Private) Limited
Email: info@digitalcode.pk
Landline: +92 51 8990491
WhatsApp: +92 300 0390491
Pakistan Address: Office 01, 3rd Floor, Plaza 153, Nasir Arcade, Bahria Town Phase 4, Civic Center, Islamabad, Pakistan
UAE Address: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE
Please do not include passwords, private keys, payment-card details, or unnecessary sensitive information in an initial security report.
