Security & Compliance

Effective Date: June 3, 2026

This Security & Compliance Statement describes the security practices, operational safeguards and compliance principles adopted by Expense India, a product operated by Journey Junction. This document is provided for informational purposes only and does not create contractual commitments beyond those expressly agreed in writing.

1. Our Commitment

Expense India is committed to maintaining commercially reasonable security practices designed to protect the confidentiality, integrity and availability of customer information.

We continuously evaluate our operational practices and may update security measures as technology, threats and business requirements evolve.

2. Security Philosophy

Our security approach focuses on:

  • Confidentiality of customer information
  • Controlled access to business data
  • Protection against unauthorized access
  • Secure operation of services
  • Monitoring and risk management
  • Operational resilience

Security is considered throughout the design, deployment and maintenance of the platform.

3. Customer Data Ownership

All customer data uploaded to Expense India remains the property of the respective registered business organization.

Journey Junction does not claim ownership of:

  • Expense records
  • Employee data
  • Reimbursement records
  • Receipts
  • Invoices
  • Approval records
  • Business documents

The customer organization remains responsible for determining:

  • What information is collected
  • Who may access information
  • How information is used internally
  • Applicable retention requirements

4. Data Processing Role

For privacy and operational purposes:

  • Customer Organization = Data Controller
  • Expense India / Journey Junction = Service Provider and Data Processor

Journey Junction processes customer information solely for the purpose of delivering the services requested by the customer.

5. Access Control

Expense India utilizes role-based access controls to help customers manage access to information. The platform may support roles such as:

  • Owner
  • Administrator
  • Manager
  • Employee

Access permissions may be configured by the customer organization. Customers remain responsible for assigning permissions appropriately within their organization.

6. Authentication and Account Security

The platform may implement security measures including:

  • User authentication
  • Password protection
  • Session management
  • Access logging
  • Permission controls

Users are responsible for:

  • Maintaining password confidentiality
  • Securing their devices
  • Preventing unauthorized account access
  • Reporting suspected account compromise

7. Infrastructure Security

Expense India may utilize reputable cloud infrastructure and service providers to support platform operations. Security practices may include:

  • Network protection controls
  • Infrastructure monitoring
  • Access restrictions
  • Administrative safeguards
  • System maintenance procedures

Infrastructure providers may maintain their own independent security programs.

8. Data Transmission

Where technically feasible and commercially reasonable, information transmitted between users and the platform may be protected using industry-standard encryption technologies. No method of transmission or storage can guarantee absolute security.

9. Data Storage

Customer information may be stored using cloud-based systems operated by Journey Junction or its service providers. Storage locations may change over time based on operational, technical or business requirements. Appropriate safeguards are implemented to protect stored information.

10. Backup and Recovery

Journey Junction may maintain backup procedures designed to support service continuity and disaster recovery. Backups are maintained for operational purposes and may be retained for varying periods. Backup restoration timelines cannot be guaranteed.

11. Logging and Monitoring

To support security, troubleshooting and operational management, the platform may generate logs relating to:

  • User access
  • Authentication events
  • Platform activity
  • System performance
  • Error conditions
  • Security events

Such logs may be used to investigate operational or security issues.

12. Security Incident Response

Journey Junction maintains procedures for evaluating and responding to identified security incidents. Response activities may include:

  • Investigation
  • Containment
  • Remediation
  • Recovery
  • Communication where appropriate

The nature and timing of notifications may depend on legal obligations, operational requirements and the circumstances of the incident.

13. Customer Responsibilities

Security is a shared responsibility. Customers are responsible for:

  • Managing user access
  • Removing access for departed employees
  • Protecting login credentials
  • Reviewing approval workflows
  • Verifying expense submissions
  • Maintaining internal controls
  • Complying with applicable laws

Journey Junction is not responsible for security incidents arising from customer negligence, misconfiguration, credential sharing or unauthorized internal access.

14. Third-Party Service Providers

Expense India may rely on third-party providers for:

  • Hosting
  • Storage
  • Communications
  • Analytics
  • Payment processing
  • Security services

While providers are selected carefully, Journey Junction does not control every aspect of third-party operations and cannot guarantee uninterrupted performance of third-party services.

15. Compliance Approach

Journey Junction seeks to operate the platform in a manner consistent with applicable legal and regulatory requirements relevant to its operations.

Compliance responsibilities relating to:

  • Accounting
  • Taxation
  • Employment
  • Corporate governance
  • Expense reimbursement
  • Internal approvals

remain the responsibility of the customer organization.

16. No Certification Claims

Unless expressly stated in a written agreement, Journey Junction does not represent that Expense India is certified under any particular security, privacy or compliance framework. Customers should not assume compliance certifications unless specifically documented by Journey Junction.

17. No Security Guarantee

Despite reasonable safeguards, no system can guarantee complete protection against:

  • Cyberattacks
  • Data breaches
  • Human error
  • Unauthorized access
  • Service interruptions
  • Hardware failures
  • Software defects
  • Internet failures

Users acknowledge and accept that all technology services involve inherent security risks.

18. Limitation of Reliance

This Security & Compliance Statement is intended to provide general information regarding our security practices. Nothing in this document shall be interpreted as:

  • A warranty
  • A guarantee
  • A service level commitment
  • A contractual promise

except where expressly agreed in a separate written agreement signed by Journey Junction.

19. Changes to This Statement

Journey Junction may modify this Security & Compliance Statement from time to time. Updated versions shall become effective upon publication. Continued use of the platform constitutes acceptance of the revised version.

20. Contact Information

For security-related questions or concerns:

Journey Junction

301 Extn-273, South Center, Masjid Moth, South Delhi, Delhi – 110049, India

Email: support@journey-junction.in

21. Responsible Disclosure

If you believe you have identified a security vulnerability affecting Expense India, please report it to: support@journey-junction.in

Please include sufficient information to assist investigation and avoid exploiting vulnerabilities beyond what is reasonably necessary to demonstrate the issue.

— End of Security & Compliance Statement —