Regulation 3(5) requires your structured digital database to be maintained internally and not outsourced. This page sets out exactly who holds which credential to an InsiderQ installation, and — more usefully — how to check it for yourself rather than take our word for it.
The position in one paragraph
The structured digital database created and maintained through InsiderQ is maintained by you, internally, on infrastructure you control. Naapbooks Limited does not maintain the database, does not hold any credential that permits access to it, and cannot read its contents. Where Naapbooks provides server infrastructure, it provides that infrastructure as a facility only: on completion of installation every administrative credential is handed to you and none is retained by Naapbooks.
This distinction is the whole of the matter. Regulation 3(5) of the SEBI (Prohibition of Insider Trading) Regulations, 2015 requires that the database “shall not be outsourced and shall be maintained internally”. SEBI’s Comprehensive FAQs dated 31 December 2024 explain at FAQ 8 that where a third-party vendor maintains the server, the vendor “may have access to such records which would be contrary to the regulations”.
The test SEBI applies is not cloud versus on-premise. It is who can reach the data.
So the question worth putting to any SDD vendor, including us, is not “is it cloud or on-premise?” but “who holds root on that server, and can any of your employees read the data?” — and to ask for the answer in writing. This page is ours.
What Naapbooks does and does not do
| Naapbooks Limited | You | |
|---|---|---|
| Owns the database and its contents | No | Yes |
| Maintains the structured digital database | No — the software is licensed; the database is maintained by your Compliance Officer and users | Yes |
| Holds server root or Administrator credentials | No — handed over at installation, none retained | Yes |
| Holds database (MySQL) credentials | No — handed over at installation, none retained | Yes |
| Holds the application administrator account | No — created in your Compliance Officer’s name at first login | Yes |
| Can read, export or copy UPSI records | No | Yes |
| Can take snapshots or backups of the data | No | Yes — backup is your responsibility, see below |
| Provides server, storage and network, where that option is taken | Yes — as a facility | — |
| Provides the software, updates and support | Yes | — |
| Determines retention and deletion | No | Yes — Regulation 3(6) |
Where a row says none retained, the Credential Handover Record signed on the day of installation is the evidence.
Deployment options, and what each means for custody
InsiderQ is deployed in an environment you designate and control. Three arrangements are offered. The custody position is identical in all three — only who buys the hardware changes.
| Option | How it works | Custody position |
|---|---|---|
| Your own premises | You install on your own server, in your own data centre or office. | You own and control the infrastructure throughout. Naapbooks assists with installation only. |
| Your own cloud tenancy | You install in your own AWS, Google Cloud, Azure or other account. | The tenancy, the billing relationship and the credentials are yours. Naapbooks never holds an account in that tenancy. |
| Infrastructure facilitated by Naapbooks | Naapbooks provisions a dedicated server or VPS on your behalf and charges for it. | Naapbooks provisions and pays the provider. At handover, root, database and application credentials pass to you and are removed from Naapbooks’ possession. You may transfer the account into your own name at any time. |
So that an organisation without server capacity is not excluded. It is a procurement convenience, not a managed service. Naapbooks does not operate the instance, does not monitor the data, and does not retain a route into it. If your Compliance Officer would prefer that Naapbooks has no relationship with the infrastructure at all, take option one or two — the software is identical.
Credential custody
At the point of installation the following are created and handed to you, and are not retained by Naapbooks:
- Server root or Administrator account and password.
- MySQL database account and password.
- The InsiderQ application administrator account, created in the name of your Compliance Officer.
- SMTP credentials, which are your own mail account throughout.
- Where infrastructure is facilitated by Naapbooks, the cloud or VPS provider console login.
The handover is recorded in a Credential Handover Record, signed by both parties on the day of installation. You are advised to rotate every credential immediately after signature, and the record carries a field confirming it was done.
After handover, Naapbooks has no standing access of any kind. There is no vendor account, no support back door, no shared administrator, and no key escrow.
Because we hold no credential, we cannot reset an application password, recover a username or unlock an account. Your Compliance Officer or another application administrator does that from inside the application. Keep at least two active administrator accounts — if the only one becomes inaccessible, recovery needs your own database administrator, and we can supply the procedure but cannot perform it.
Where Naapbooks facilitates infrastructure
What is supplied is compute, storage and network capacity, with the operating system installed and the prerequisites configured. The following are stated here because they are the points an inspector asks about:
- Naapbooks does not hold a console, SSH, RDP or database credential for the instance after handover.
- Naapbooks does not take, hold or store snapshots, images or backups of the instance or its data.
- Naapbooks does not configure agents, monitoring or logging that transmit application data off the instance.
- The underlying cloud or hosting provider is a passive infrastructure supplier, in the same sense that a landlord is passive; it is not given application or database credentials.
- If the account is held in Naapbooks’ name for billing purposes, you may require its transfer to your own name at any time, at no charge.
Backup, and why it is yours
Backup and recovery of the database is your responsibility, in every deployment option. This is deliberate, and it follows from the section above: a party that cannot read the data cannot back it up. Naapbooks provides the backup procedure in the installation documentation, will configure a backup job to a destination you nominate and control, and will assist with restoration on request — but the backup destination, the credentials for it and the copies themselves are yours.
Retention and deletion
Regulation 3(6) requires the database to be preserved for not less than eight years after completion of the relevant transactions, and, where you receive information from SEBI regarding an investigation or enforcement proceeding, until those proceedings are complete. Retention periods are configured and enforced by you. Naapbooks does not delete your data, and holds no copy that would need deleting on termination.
On termination of the licence you retain the database and the server. Naapbooks’ obligations end with support; nothing has to be returned, because nothing was held.
How to verify every statement on this page
Every control above is checkable. You, your Practising Company Secretary or an inspecting official may:
| Statement | How to verify it |
|---|---|
| Naapbooks holds no server credential | Review the Credential Handover Record; audit the server’s user accounts and authorised keys; rotate the credentials and confirm support continues to function. |
| Naapbooks holds no database credential | Review the MySQL user accounts on the instance. |
| Naapbooks holds no application account | Review the InsiderQ user list, which is visible to the Compliance Officer and shows every account and its role. |
| No data leaves the instance | Review outbound network configuration. The only outbound requirement is SMTP to your own mail server for notifications. |
| Every action is recorded | Open the Audit Logs report in InsiderQ, which records all activity in the application. |
| The instance is under your control | Change the root password. Nothing in the service depends on Naapbooks retaining it. |
That last one is the whole test, and it takes five minutes. If a vendor’s support stops working after you rotate your own root password, that vendor was relying on retained access. Run it on us, and on anyone else you are evaluating.
What this statement does not claim
Three things, stated plainly, because vendors in this market are not always careful about them.
- Compliance with the PIT Regulations is the obligation of the listed entity, intermediary or fiduciary — not of its software supplier. InsiderQ is built to support those requirements. It cannot discharge them, and no software can.
- There is no SEBI certification, approval or empanelment of structured digital database software. Naapbooks does not hold one, and neither does any other vendor. Any claim to the contrary, from any supplier, should be asked to name the certifying body.
- This statement describes controls, not outcomes. It does not predict the result of any inspection, adjudication or proceeding.
Standards Naapbooks does hold
Naapbooks Limited is certified to ISO 9001:2015 and ISO/IEC 27001:2022, and is appraised at CMMI Maturity Level 3. Certificate numbers, the certifying bodies and validity dates are available on request.
Naapbooks Limited is itself listed on the BSE SME platform, scrip code 543351. It is itself subject to the PIT Regulations, it maintains its own structured digital database, and it maintains it in InsiderQ.
Questions about any of this? We answer them from the compliance officer’s side of the table, not the sales side.
Talk to usVersion 1.0 · effective 3rd May 2025. Issued as a standing document and version-controlled.
Read with the Service Levels, the System Requirements and the Terms and Conditions.