SEBI PIT and SDD Software FAQs

Common questions on the SEBI (Prohibition of Insider Trading) Regulations, 2015 and on Structured Digital Database software — who has to maintain an SDD, what it must record, how long records are retained, and how InsiderQ is deployed. Pricing depends on entities and users and is quoted per client; ask for a quotation.

Yes. Regulation 3(5) of the SEBI (Prohibition of Insider Trading) Regulations, 2015 requires the board of directors, or the head of the organisation, of every person required to handle unpublished price sensitive information to maintain a structured digital database. The regulation also says it shall not be outsourced and shall be maintained internally.

The identity of every person who shared unpublished price sensitive information and of every person who received it, with a permanent identifier such as PAN, together with the nature of the information. Regulation 3(5) further requires adequate internal controls, time stamping and audit trails, so that an entry cannot be altered without leaving a trace.

Regulation 3(6) requires the database to be preserved for not less than eight years after completion of the relevant transactions, and where any SEBI proceeding has begun, until that proceeding is concluded. Retention is configured inside InsiderQ, but the eight-year horizon also depends on your own backup regime, which remains your responsibility.

Four roles: Compliance Officer, Designated Person, Connected Person and Practising Company Secretary. The Compliance Officer administers the instance; designated and connected persons record or acknowledge the UPSI they share or receive; the PCS role gives the read access needed for certification. Accounts can be disabled rather than deleted, which preserves the audit trail.

InsiderQ produces the UPSI Statement and the Audit Logs report, filtered to any period and exportable to PDF or Excel — the records that the six certification points in the exchanges’ circulars of 18 October 2024 (NSE/CML/2024/31 and BSE notice 20241018-44) are evidenced against. The obligation itself stays with the entity: the software records and evidences compliance, it does not discharge it.

Their own. Regulation 3(5) is written around every person required to handle unpublished price sensitive information, which takes in brokers, merchant bankers, asset management companies, registrars and transfer agents, portfolio managers and investment advisers. Regulation 9A and Schedule C reinforce it, and SEBI’s Comprehensive FAQs dated 31 December 2024 confirm the position at FAQs 5 and 6.

Yes. A single InsiderQ instance records UPSI for multiple client entities, with separate records and separate reporting per entity, so a report produced for one client never exposes another’s information. The licence covers one production instance per entity; a test or UAT environment is licensed separately.

The question that decides compliance is not cloud versus on-premise, it is who can reach the data. SEBI’s Comprehensive FAQs of 31 December 2024 permit cloud hosting at FAQ 7 where the board and compliance officer retain accountability for confidentiality, integrity and security, and warn at FAQ 8 that where a third-party vendor maintains the server on a login basis the vendor “may have access to such records which would be contrary to the regulations”. InsiderQ installs on your own premises, in your own cloud tenancy, or on infrastructure Naapbooks provisions for you — and in all three every credential passes to you at installation and none is retained.

A server on Ubuntu LTS or Windows Server 2019 and above, with MySQL 8, Node.js 18, IIS 8 or above or Nginx, 8 GB RAM and 100 GB free disk for the recommended configuration — plus a static IP address, a TLS certificate for the hostname, and SMTP credentials on your own mail service. The full specification is on the System Requirements page.

The UPSI Statement for the period and the Audit Logs report, both exportable to PDF or Excel from your own installation. There is no prescribed filing format for a structured digital database and nothing is submitted to SEBI routinely — the records are produced to auditors, to a Practising Company Secretary or to an inspecting authority when called for.

Any professional who handles unpublished price sensitive information while advising or serving a listed entity — company secretaries in practice, chartered accountants, law firms, valuers, bankers and consultants. Regulation 3(5) is framed around the handling of UPSI rather than the type of firm, so the obligation follows the information.

No. The requirement attaches to handling UPSI, and receiving it is handling it. Your database has to record who passed the information to the firm, who inside the firm received it, and the nature of what was shared.

Yes. InsiderQ keeps a separate record set and separate reporting for each client entity inside one installation, and access is role-based, so a partner working on one engagement does not see another’s UPSI. Every access is written to the audit log.

You export the UPSI Statement for the period and the Audit Logs from your own installation. Because the software runs on infrastructure you control, you can produce the records without involving Naapbooks and without any third party having had access to them.

No. SEBI does not certify, approve or empanel structured digital database software — for any vendor, and any claim to the contrary should be treated with suspicion. What is certified is the entity’s maintenance of the database, and since the exchanges’ circulars of 18 October 2024 that annual confirmation is issued by a Practising Company Secretary.

Three arrangements: your own premises, your own cloud tenancy, or infrastructure Naapbooks provisions on your behalf. The software and the custody position are identical in all three — at installation the server, database and application administrator credentials pass to you, a Credential Handover Record is signed, and Naapbooks retains none of them. The Data Custody and Access statement sets out what to verify and how to verify it yourself.

No — and that is a consequence of the custody position rather than a policy. Naapbooks holds no credential to your installation, so it cannot reset an application password or recover a username. Keep two active administrator accounts; if a sole administrator is locked out, recovery has to be carried out by your own database administrator.

Support runs 10:00 to 18:00 India Standard Time, Monday to Friday, excluding national holidays, through the support portal, support@naapbooks.com or the in-application help icon. A P1 critical fault is acknowledged within 30 minutes, responded to within 2 hours and resolved or worked around within 6. The full severity table, escalation path and availability commitment are on the Service Levels page. Naapbooks will never ask you for a password, a login or a one-time code.

Pricing depends on the entity type, the number of designated and connected persons and the deployment arrangement, so it is quoted per client rather than published. Ask for a quotation and you will receive a written one covering licence, installation and support.

The current and immediately preceding major versions of Google Chrome, Microsoft Edge and Mozilla Firefox. Notifications and alerts are sent using SMTP credentials on your own mail service, so mail leaves your domain through your server — Naapbooks does not relay it, and deliverability stays under your IT team’s control.