Data Custody and Access

Naapbooks holds no credential to your InsiderQ installation. The server, the operating system, the database and the application administrator accounts are all yours — which is why we cannot reset an application password for you. This page sets out who can reach the data and what your Practising Company Secretary can verify independently.

Version 1.0Effective 3rd May 2025Naapbooks Limited · BSE SME 543351

Regulation 3(5) requires your structured digital database to be maintained internally and not outsourced. This page sets out exactly who holds which credential to an InsiderQ installation, and — more usefully — how to check it for yourself rather than take our word for it.

The position in one paragraph

The structured digital database created and maintained through InsiderQ is maintained by you, internally, on infrastructure you control. Naapbooks Limited does not maintain the database, does not hold any credential that permits access to it, and cannot read its contents. Where Naapbooks provides server infrastructure, it provides that infrastructure as a facility only: on completion of installation every administrative credential is handed to you and none is retained by Naapbooks.

This distinction is the whole of the matter. Regulation 3(5) of the SEBI (Prohibition of Insider Trading) Regulations, 2015 requires that the database “shall not be outsourced and shall be maintained internally”. SEBI’s Comprehensive FAQs dated 31 December 2024 explain at FAQ 8 that where a third-party vendor maintains the server, the vendor “may have access to such records which would be contrary to the regulations”.

The test SEBI applies is not cloud versus on-premise. It is who can reach the data.

So the question worth putting to any SDD vendor, including us, is not “is it cloud or on-premise?” but “who holds root on that server, and can any of your employees read the data?” — and to ask for the answer in writing. This page is ours.

What Naapbooks does and does not do

Naapbooks LimitedYou
Owns the database and its contentsNoYes
Maintains the structured digital databaseNo — the software is licensed; the database is maintained by your Compliance Officer and usersYes
Holds server root or Administrator credentialsNo — handed over at installation, none retainedYes
Holds database (MySQL) credentialsNo — handed over at installation, none retainedYes
Holds the application administrator accountNo — created in your Compliance Officer’s name at first loginYes
Can read, export or copy UPSI recordsNoYes
Can take snapshots or backups of the dataNoYes — backup is your responsibility, see below
Provides server, storage and network, where that option is takenYes — as a facility
Provides the software, updates and supportYes
Determines retention and deletionNoYes — Regulation 3(6)

Where a row says none retained, the Credential Handover Record signed on the day of installation is the evidence.

Deployment options, and what each means for custody

InsiderQ is deployed in an environment you designate and control. Three arrangements are offered. The custody position is identical in all three — only who buys the hardware changes.

OptionHow it worksCustody position
Your own premisesYou install on your own server, in your own data centre or office.You own and control the infrastructure throughout. Naapbooks assists with installation only.
Your own cloud tenancyYou install in your own AWS, Google Cloud, Azure or other account.The tenancy, the billing relationship and the credentials are yours. Naapbooks never holds an account in that tenancy.
Infrastructure facilitated by NaapbooksNaapbooks provisions a dedicated server or VPS on your behalf and charges for it.Naapbooks provisions and pays the provider. At handover, root, database and application credentials pass to you and are removed from Naapbooks’ possession. You may transfer the account into your own name at any time.
Why the third option exists

So that an organisation without server capacity is not excluded. It is a procurement convenience, not a managed service. Naapbooks does not operate the instance, does not monitor the data, and does not retain a route into it. If your Compliance Officer would prefer that Naapbooks has no relationship with the infrastructure at all, take option one or two — the software is identical.

Credential custody

At the point of installation the following are created and handed to you, and are not retained by Naapbooks:

  • Server root or Administrator account and password.
  • MySQL database account and password.
  • The InsiderQ application administrator account, created in the name of your Compliance Officer.
  • SMTP credentials, which are your own mail account throughout.
  • Where infrastructure is facilitated by Naapbooks, the cloud or VPS provider console login.

The handover is recorded in a Credential Handover Record, signed by both parties on the day of installation. You are advised to rotate every credential immediately after signature, and the record carries a field confirming it was done.

After handover, Naapbooks has no standing access of any kind. There is no vendor account, no support back door, no shared administrator, and no key escrow.

A consequence worth knowing before you need it

Because we hold no credential, we cannot reset an application password, recover a username or unlock an account. Your Compliance Officer or another application administrator does that from inside the application. Keep at least two active administrator accounts — if the only one becomes inaccessible, recovery needs your own database administrator, and we can supply the procedure but cannot perform it.

Where Naapbooks facilitates infrastructure

What is supplied is compute, storage and network capacity, with the operating system installed and the prerequisites configured. The following are stated here because they are the points an inspector asks about:

  • Naapbooks does not hold a console, SSH, RDP or database credential for the instance after handover.
  • Naapbooks does not take, hold or store snapshots, images or backups of the instance or its data.
  • Naapbooks does not configure agents, monitoring or logging that transmit application data off the instance.
  • The underlying cloud or hosting provider is a passive infrastructure supplier, in the same sense that a landlord is passive; it is not given application or database credentials.
  • If the account is held in Naapbooks’ name for billing purposes, you may require its transfer to your own name at any time, at no charge.

Backup, and why it is yours

Backup and recovery of the database is your responsibility, in every deployment option. This is deliberate, and it follows from the section above: a party that cannot read the data cannot back it up. Naapbooks provides the backup procedure in the installation documentation, will configure a backup job to a destination you nominate and control, and will assist with restoration on request — but the backup destination, the credentials for it and the copies themselves are yours.

Retention and deletion

Regulation 3(6) requires the database to be preserved for not less than eight years after completion of the relevant transactions, and, where you receive information from SEBI regarding an investigation or enforcement proceeding, until those proceedings are complete. Retention periods are configured and enforced by you. Naapbooks does not delete your data, and holds no copy that would need deleting on termination.

On termination of the licence you retain the database and the server. Naapbooks’ obligations end with support; nothing has to be returned, because nothing was held.

How to verify every statement on this page

Every control above is checkable. You, your Practising Company Secretary or an inspecting official may:

StatementHow to verify it
Naapbooks holds no server credentialReview the Credential Handover Record; audit the server’s user accounts and authorised keys; rotate the credentials and confirm support continues to function.
Naapbooks holds no database credentialReview the MySQL user accounts on the instance.
Naapbooks holds no application accountReview the InsiderQ user list, which is visible to the Compliance Officer and shows every account and its role.
No data leaves the instanceReview outbound network configuration. The only outbound requirement is SMTP to your own mail server for notifications.
Every action is recordedOpen the Audit Logs report in InsiderQ, which records all activity in the application.
The instance is under your controlChange the root password. Nothing in the service depends on Naapbooks retaining it.

That last one is the whole test, and it takes five minutes. If a vendor’s support stops working after you rotate your own root password, that vendor was relying on retained access. Run it on us, and on anyone else you are evaluating.

What this statement does not claim

Three things, stated plainly, because vendors in this market are not always careful about them.

  • Compliance with the PIT Regulations is the obligation of the listed entity, intermediary or fiduciary — not of its software supplier. InsiderQ is built to support those requirements. It cannot discharge them, and no software can.
  • There is no SEBI certification, approval or empanelment of structured digital database software. Naapbooks does not hold one, and neither does any other vendor. Any claim to the contrary, from any supplier, should be asked to name the certifying body.
  • This statement describes controls, not outcomes. It does not predict the result of any inspection, adjudication or proceeding.

Standards Naapbooks does hold

Naapbooks Limited is certified to ISO 9001:2015 and ISO/IEC 27001:2022, and is appraised at CMMI Maturity Level 3. Certificate numbers, the certifying bodies and validity dates are available on request.

Naapbooks Limited is itself listed on the BSE SME platform, scrip code 543351. It is itself subject to the PIT Regulations, it maintains its own structured digital database, and it maintains it in InsiderQ.

Questions about any of this? We answer them from the compliance officer’s side of the table, not the sales side.

Talk to us

Version 1.0 · effective 3rd May 2025. Issued as a standing document and version-controlled.

Read with the Service Levels, the System Requirements and the Terms and Conditions.