Security & Compliance
Effective Date: June 3, 2026
This Security & Compliance Statement describes the security practices, operational safeguards and compliance principles adopted by Expense India, a product operated by Journey Junction. This document is provided for informational purposes only and does not create contractual commitments beyond those expressly agreed in writing.
1. Our Commitment
Expense India is committed to maintaining commercially reasonable security practices designed to protect the confidentiality, integrity and availability of customer information.
We continuously evaluate our operational practices and may update security measures as technology, threats and business requirements evolve.
2. Security Philosophy
Our security approach focuses on:
- Confidentiality of customer information
- Controlled access to business data
- Protection against unauthorized access
- Secure operation of services
- Monitoring and risk management
- Operational resilience
Security is considered throughout the design, deployment and maintenance of the platform.
3. Customer Data Ownership
All customer data uploaded to Expense India remains the property of the respective registered business organization.
Journey Junction does not claim ownership of:
- Expense records
- Employee data
- Reimbursement records
- Receipts
- Invoices
- Approval records
- Business documents
The customer organization remains responsible for determining:
- What information is collected
- Who may access information
- How information is used internally
- Applicable retention requirements
4. Data Processing Role
For privacy and operational purposes:
- Customer Organization = Data Controller
- Expense India / Journey Junction = Service Provider and Data Processor
Journey Junction processes customer information solely for the purpose of delivering the services requested by the customer.
5. Access Control
Expense India utilizes role-based access controls to help customers manage access to information. The platform may support roles such as:
- Owner
- Administrator
- Manager
- Employee
Access permissions may be configured by the customer organization. Customers remain responsible for assigning permissions appropriately within their organization.
6. Authentication and Account Security
The platform may implement security measures including:
- User authentication
- Password protection
- Session management
- Access logging
- Permission controls
Users are responsible for:
- Maintaining password confidentiality
- Securing their devices
- Preventing unauthorized account access
- Reporting suspected account compromise
7. Infrastructure Security
Expense India may utilize reputable cloud infrastructure and service providers to support platform operations. Security practices may include:
- Network protection controls
- Infrastructure monitoring
- Access restrictions
- Administrative safeguards
- System maintenance procedures
Infrastructure providers may maintain their own independent security programs.
8. Data Transmission
Where technically feasible and commercially reasonable, information transmitted between users and the platform may be protected using industry-standard encryption technologies. No method of transmission or storage can guarantee absolute security.
9. Data Storage
Customer information may be stored using cloud-based systems operated by Journey Junction or its service providers. Storage locations may change over time based on operational, technical or business requirements. Appropriate safeguards are implemented to protect stored information.
10. Backup and Recovery
Journey Junction may maintain backup procedures designed to support service continuity and disaster recovery. Backups are maintained for operational purposes and may be retained for varying periods. Backup restoration timelines cannot be guaranteed.
11. Logging and Monitoring
To support security, troubleshooting and operational management, the platform may generate logs relating to:
- User access
- Authentication events
- Platform activity
- System performance
- Error conditions
- Security events
Such logs may be used to investigate operational or security issues.
12. Security Incident Response
Journey Junction maintains procedures for evaluating and responding to identified security incidents. Response activities may include:
- Investigation
- Containment
- Remediation
- Recovery
- Communication where appropriate
The nature and timing of notifications may depend on legal obligations, operational requirements and the circumstances of the incident.
13. Customer Responsibilities
Security is a shared responsibility. Customers are responsible for:
- Managing user access
- Removing access for departed employees
- Protecting login credentials
- Reviewing approval workflows
- Verifying expense submissions
- Maintaining internal controls
- Complying with applicable laws
Journey Junction is not responsible for security incidents arising from customer negligence, misconfiguration, credential sharing or unauthorized internal access.
14. Third-Party Service Providers
Expense India may rely on third-party providers for:
- Hosting
- Storage
- Communications
- Analytics
- Payment processing
- Security services
While providers are selected carefully, Journey Junction does not control every aspect of third-party operations and cannot guarantee uninterrupted performance of third-party services.
15. Compliance Approach
Journey Junction seeks to operate the platform in a manner consistent with applicable legal and regulatory requirements relevant to its operations.
Compliance responsibilities relating to:
- Accounting
- Taxation
- Employment
- Corporate governance
- Expense reimbursement
- Internal approvals
remain the responsibility of the customer organization.
16. No Certification Claims
Unless expressly stated in a written agreement, Journey Junction does not represent that Expense India is certified under any particular security, privacy or compliance framework. Customers should not assume compliance certifications unless specifically documented by Journey Junction.
17. No Security Guarantee
Despite reasonable safeguards, no system can guarantee complete protection against:
- Cyberattacks
- Data breaches
- Human error
- Unauthorized access
- Service interruptions
- Hardware failures
- Software defects
- Internet failures
Users acknowledge and accept that all technology services involve inherent security risks.
18. Limitation of Reliance
This Security & Compliance Statement is intended to provide general information regarding our security practices. Nothing in this document shall be interpreted as:
- A warranty
- A guarantee
- A service level commitment
- A contractual promise
except where expressly agreed in a separate written agreement signed by Journey Junction.
19. Changes to This Statement
Journey Junction may modify this Security & Compliance Statement from time to time. Updated versions shall become effective upon publication. Continued use of the platform constitutes acceptance of the revised version.
20. Contact Information
For security-related questions or concerns:
Journey Junction
301 Extn-273, South Center, Masjid Moth, South Delhi, Delhi – 110049, India
Email: support@journey-junction.in
21. Responsible Disclosure
If you believe you have identified a security vulnerability affecting Expense India, please report it to: support@journey-junction.in
Please include sufficient information to assist investigation and avoid exploiting vulnerabilities beyond what is reasonably necessary to demonstrate the issue.
— End of Security & Compliance Statement —
