Skip to content

Revzio — Security Awareness Training

Field Value
Owner Puneet Gupta (Co-Founder)
Audience All personnel (employees + contractors)
Cadence On onboarding + at least annually
Version 1.0
Date 2026-06-11

Slide-by-slide content. Backs the Security Awareness & Training Policy (docs/security/15-security-awareness-training-policy.md), CoinDCX questionnaire Sno 58, and Requested Document r17. Each --- marks a new slide. Export to .pptx/PDF for delivery.


Slide 1 — Security Awareness Training

Revzio · Protecting our customers' financial data

Presenter: Puneet Gupta (Co-Founder) · Date: (completed at each delivery)

"Security is everyone's job — not just engineering's."


Slide 2 — Why this matters

  • We handle customers' financial and accounting data — invoices, payments, bank transactions, and personal data.
  • Our customers include regulated businesses (e.g. a crypto exchange) who trust us to protect their data.
  • A single mistake — a reused password, a clicked phishing link, a lost laptop — can cause a breach that damages customers and the company.
  • This training covers how to recognize and prevent the most common threats.

Slide 3 — Our responsibility & data classification

  • Revzio is a data processor — we process customer data only as instructed, and protect it.
  • Highest sensitivity: customer financial records, personal data, and integration credentials.
  • Treat all customer data as confidential. Access only what your role requires (need-to-know).
  • Never copy customer data to personal storage, chats, or unapproved tools.

Slide 4 — Phishing & social engineering (1)

Phishing is the #1 way attackers get in. Watch for:

  • Urgency or pressure ("act now", "your account will be closed").
  • Unexpected attachments or links.
  • Sender addresses that look almost right (lookalike domains).
  • Requests for credentials, MFA codes, or to change payment details.

Slide 5 — Phishing & social engineering (2): what to do

  • Stop and verify before clicking links or opening attachments.
  • Hover over links to see the real destination; when in doubt, don't click.
  • Never share passwords or MFA codes — no legitimate party will ask for them.
  • Verify unusual requests (payments, credential changes) through a second channel.
  • Report suspicious messages immediately (see the last slide).

Slide 6 — Passwords & authentication

  • Use a strong, unique password for every system — minimum 12 characters, mixing upper/lower/numbers/symbols.
  • Never reuse passwords across work and personal accounts.
  • Use a password manager — don't store passwords in notes, spreadsheets, or browsers you share.
  • Enable multi-factor authentication (MFA) wherever available.
  • Never share accounts; every person uses their own login.

Slide 7 — Device security (BYOD)

Your laptop accesses customer data — keep it safe:

  • Full-disk encryption ON (FileVault / BitLocker).
  • Auto screen-lock with a short timeout + strong passcode/biometric.
  • Keep the OS and apps updated — enable automatic updates.
  • Anti-malware enabled.
  • Don't install untrusted software or browser extensions.
  • Report a lost or stolen device immediately so access can be revoked/wiped.

Slide 8 — Data handling

  • Keep customer data inside approved systems (the platform, the managed database) — not on USB drives, personal cloud, or local downloads.
  • Don't paste customer/PII data into unapproved third-party tools or AI assistants.
  • Share data only with authorized people, over approved channels.
  • Delete data you no longer need, per the Data Retention Policy.

Slide 9 — Credentials & secrets

  • Never commit secrets (API keys, passwords, tokens) to source code.
  • Store secrets in approved secret stores / environment configuration.
  • Integration credentials are encrypted — don't extract or copy them out.
  • If you think a secret was exposed, rotate it and report it immediately.

Slide 10 — Safe working habits

  • Lock your screen when you step away (Win+L / Ctrl-Cmd-Q).
  • Be careful on public Wi-Fi; prefer trusted networks.
  • Watch for shoulder-surfing in public spaces.
  • Verify before granting access or sharing — apply least privilege.
  • Keep work and personal activity separate on your device.

Slide 11 — Recognizing & reporting incidents

What is an incident? Anything that may compromise data or systems — a clicked phishing link, lost device, suspicious login, accidental data exposure, or malware.

Golden rule: when in doubt, report it — fast and no blame. Early reporting limits damage.

  • Reporting a suspected incident is never punished; hiding one is.

Slide 12 — How to report

  • Who to contact: Puneet Gupta (Incident Lead) — infra@revzio.ai
  • How: Email infra@revzio.ai (and the internal team channel).
  • What to include: what happened, when, what systems/data may be involved, and any actions you've already taken.
  • For a lost/stolen device or exposed credential, report immediately — minutes matter.

See the Incident Response Plan (docs/security/18-incident-response-plan.md).


Slide 13 — Your commitments

By working at Revzio you agree to:

  • Follow the Acceptable Use, BYOD, and security policies.
  • Protect customer data as if it were your own.
  • Complete this training on joining and annually.
  • Report security concerns promptly.

Acknowledgement: Completion is recorded via a Google Form sign-off.


Slide 14 — Key takeaways

  1. Think before you click — phishing is the top threat.
  2. Strong, unique passwords + MFA everywhere.
  3. Keep your device encrypted, locked, and updated.
  4. Keep customer data in approved systems only.
  5. When in doubt, report it.

Questions? infra@revzio.ai