Revzio — Security Awareness Training¶
| Field | Value |
|---|---|
| Owner | Puneet Gupta (Co-Founder) |
| Audience | All personnel (employees + contractors) |
| Cadence | On onboarding + at least annually |
| Version | 1.0 |
| Date | 2026-06-11 |
Slide-by-slide content. Backs the Security Awareness & Training Policy (docs/security/15-security-awareness-training-policy.md), CoinDCX questionnaire Sno 58, and Requested Document r17. Each
---marks a new slide. Export to .pptx/PDF for delivery.
Slide 1 — Security Awareness Training¶
Revzio · Protecting our customers' financial data
Presenter: Puneet Gupta (Co-Founder) · Date: (completed at each delivery)
"Security is everyone's job — not just engineering's."
Slide 2 — Why this matters¶
- We handle customers' financial and accounting data — invoices, payments, bank transactions, and personal data.
- Our customers include regulated businesses (e.g. a crypto exchange) who trust us to protect their data.
- A single mistake — a reused password, a clicked phishing link, a lost laptop — can cause a breach that damages customers and the company.
- This training covers how to recognize and prevent the most common threats.
Slide 3 — Our responsibility & data classification¶
- Revzio is a data processor — we process customer data only as instructed, and protect it.
- Highest sensitivity: customer financial records, personal data, and integration credentials.
- Treat all customer data as confidential. Access only what your role requires (need-to-know).
- Never copy customer data to personal storage, chats, or unapproved tools.
Slide 4 — Phishing & social engineering (1)¶
Phishing is the #1 way attackers get in. Watch for:
- Urgency or pressure ("act now", "your account will be closed").
- Unexpected attachments or links.
- Sender addresses that look almost right (lookalike domains).
- Requests for credentials, MFA codes, or to change payment details.
Slide 5 — Phishing & social engineering (2): what to do¶
- Stop and verify before clicking links or opening attachments.
- Hover over links to see the real destination; when in doubt, don't click.
- Never share passwords or MFA codes — no legitimate party will ask for them.
- Verify unusual requests (payments, credential changes) through a second channel.
- Report suspicious messages immediately (see the last slide).
Slide 6 — Passwords & authentication¶
- Use a strong, unique password for every system — minimum 12 characters, mixing upper/lower/numbers/symbols.
- Never reuse passwords across work and personal accounts.
- Use a password manager — don't store passwords in notes, spreadsheets, or browsers you share.
- Enable multi-factor authentication (MFA) wherever available.
- Never share accounts; every person uses their own login.
Slide 7 — Device security (BYOD)¶
Your laptop accesses customer data — keep it safe:
- Full-disk encryption ON (FileVault / BitLocker).
- Auto screen-lock with a short timeout + strong passcode/biometric.
- Keep the OS and apps updated — enable automatic updates.
- Anti-malware enabled.
- Don't install untrusted software or browser extensions.
- Report a lost or stolen device immediately so access can be revoked/wiped.
Slide 8 — Data handling¶
- Keep customer data inside approved systems (the platform, the managed database) — not on USB drives, personal cloud, or local downloads.
- Don't paste customer/PII data into unapproved third-party tools or AI assistants.
- Share data only with authorized people, over approved channels.
- Delete data you no longer need, per the Data Retention Policy.
Slide 9 — Credentials & secrets¶
- Never commit secrets (API keys, passwords, tokens) to source code.
- Store secrets in approved secret stores / environment configuration.
- Integration credentials are encrypted — don't extract or copy them out.
- If you think a secret was exposed, rotate it and report it immediately.
Slide 10 — Safe working habits¶
- Lock your screen when you step away (Win+L / Ctrl-Cmd-Q).
- Be careful on public Wi-Fi; prefer trusted networks.
- Watch for shoulder-surfing in public spaces.
- Verify before granting access or sharing — apply least privilege.
- Keep work and personal activity separate on your device.
Slide 11 — Recognizing & reporting incidents¶
What is an incident? Anything that may compromise data or systems — a clicked phishing link, lost device, suspicious login, accidental data exposure, or malware.
Golden rule: when in doubt, report it — fast and no blame. Early reporting limits damage.
- Reporting a suspected incident is never punished; hiding one is.
Slide 12 — How to report¶
- Who to contact: Puneet Gupta (Incident Lead) — infra@revzio.ai
- How: Email infra@revzio.ai (and the internal team channel).
- What to include: what happened, when, what systems/data may be involved, and any actions you've already taken.
- For a lost/stolen device or exposed credential, report immediately — minutes matter.
See the Incident Response Plan (docs/security/18-incident-response-plan.md).
Slide 13 — Your commitments¶
By working at Revzio you agree to:
- Follow the Acceptable Use, BYOD, and security policies.
- Protect customer data as if it were your own.
- Complete this training on joining and annually.
- Report security concerns promptly.
Acknowledgement: Completion is recorded via a Google Form sign-off.
Slide 14 — Key takeaways¶
- Think before you click — phishing is the top threat.
- Strong, unique passwords + MFA everywhere.
- Keep your device encrypted, locked, and updated.
- Keep customer data in approved systems only.
- When in doubt, report it.
Questions? infra@revzio.ai