|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Mar. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
Cybersecurity attacks impact businesses and organizations of all sizes and sectors on a global basis. At Zoomcar, we recognize the importance of developing, implementing and maintaining a cybersecurity risk management program. Our customers rely on our solutions to store, use and protect their files, which may include confidential or personally identifiable information, critical business information, photographs, and other meaningful content. A successful cybersecurity attack could adversely affect the confidentiality, integrity, and availability of our information systems or any data residing therein. We dedicate significant effort and resources to protect our systems and data, as well as the data of our customers from cybersecurity threats. We are dependent on internal and external information technology systems and infrastructure to securely process, transmit, and store critical information. Our Internal Security team is responsible for overseeing our cybersecurity. We seek to reduce cybersecurity risks through a variety of cybersecurity risk management activities that are designed to identify, assess, manage and mitigate cybersecurity threats.
Risk Management Strategy
The Company’s cybersecurity risk management program is focused on the following key areas:
Our Board of Directors, through its Audit Committee, provide oversight of our cybersecurity risk management. The Audit Committee bi-annually reviews and receives updates from the management and the Internal Security Team, including briefings on recent developments, key initiatives to strengthen our systems, applicable industry standards, incident response preparedness, compliance with regulatory requirements, vulnerability assessments, third-party and independent reviews, and other information security considerations. Our Internal Security Team also frequently engages with key vendors, industry groups, and law enforcement communities as part of our continuing efforts to improve our cybersecurity program.
We regularly review and update our policies, procedures, processes and practices to address changes in the threat landscape and as a result of lessons learned from suspected, actual or simulated incidents. We also conduct tabletop exercises, and engage third party services to conduct evaluations of our security controls through penetration testing and independent audits. We also review industry best practices to assist in evaluating responses to new challenges and risks. These evaluations include testing both the design and operational effectiveness of security controls.
Experience:
Our Director DevSecOps, Mr. Mohit Kumar, is a seasoned technology leader with over 15 years of experience in DevOps, SRE, Cloud Computing, and Cybersecurity. As the Deputy Director of DevOps and Cybersecurity at Zoomcar, Mohit heads the DevSecOps team and has led transformative projects, cultivated cybersecurity awareness and promoting holistic cybersecurity practices that were aligned with policies defined and approved by management. Mohit and his team are dedicated to integrating security into development, ensuring robust cloud security, enforcing security policies, and driving shift-left practices with operational excellence at Zoomcar.
Vishal Ramrakhyani, our Head of Engineering, has over 14 years of experience as a seasoned technology leader and operator with expertise in application development, IT, cybersecurity, data protection and governance. He has been associated with Zoomcar for more than 8 years and has led strategic initiatives to build robust cybersecurity practices that align with long-term business objectives. Vishal has also worked with internal DevSecOps and external security consultants to build policies around disaster recovery and incident response keeping business continuity as the core objective. Before Zoomcar, Vishal worked as an engineering leader in multiple startups in India.
Cybersecurity Risks
While we dedicate significant efforts and resources to our cybersecurity program, we may be unable to successfully identify threats, prevent attacks, satisfactorily resolve cybersecurity incidents, or implement adequate mitigating controls. Recently, on June 9, 2025, we identified a cybersecurity incident involving unauthorized access to our information systems, which is described in our Current Report on Form 8-K filed with the SEC on June 13 2025 (the “Cybersecurity Incident”). We have not yet fully determined the materiality of the Cybersecurity Incident. Any breach of our network security and information systems or other cybersecurity-related incidents that results in, or may result in, the loss, theft or unauthorized disclosure of data, or any delay in determining the full extent of a potential breach, could have a material adverse impact on our business, results of operations, and financial condition, including harm to our reputation and brand, reduced demand for our solutions, time-consuming and expensive litigation, fines, penalties, and other damages. To date and except as otherwise may be noted in this Annual Report on Form 10-K, we do not believe that any cybersecurity threats, including as a result of any previous cybersecurity incidents have materially affected, or are reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition. For more information relating to cybersecurity risks and uncertainties, please see the risk factor entitled “Breaches and other types of security incidents of our networks or systems similar to the recent Cybersecurity Incident, or those of our third-party service providers, could negatively impact our business, our brand and reputation, our ability to retain existing Hosts and Guests and attract new Hosts and Guests, may cause us to incur significant liabilities and adversely affect our business, results of operations, financial condition, and future prospects.” in Part I, Item 1A, and other risk factors in this 10-K.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our Internal Security team is responsible for overseeing our cybersecurity.
|Cybersecurity Risk Role of Management [Text Block]
|
Risk Management Strategy
The Company’s cybersecurity risk management program is focused on the following key areas:
Our Board of Directors, through its Audit Committee, provide oversight of our cybersecurity risk management. The Audit Committee bi-annually reviews and receives updates from the management and the Internal Security Team, including briefings on recent developments, key initiatives to strengthen our systems, applicable industry standards, incident response preparedness, compliance with regulatory requirements, vulnerability assessments, third-party and independent reviews, and other information security considerations. Our Internal Security Team also frequently engages with key vendors, industry groups, and law enforcement communities as part of our continuing efforts to improve our cybersecurity program.
We regularly review and update our policies, procedures, processes and practices to address changes in the threat landscape and as a result of lessons learned from suspected, actual or simulated incidents. We also conduct tabletop exercises, and engage third party services to conduct evaluations of our security controls through penetration testing and independent audits. We also review industry best practices to assist in evaluating responses to new challenges and risks. These evaluations include testing both the design and operational effectiveness of security controls.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Our cybersecurity efforts include the use of risk-based administrative, technical, and physical controls. Zoomcar has implemented an extensive set of policies, procedures, systems and tools designed to help safeguard our systems and data, including firewalls, intrusion detection systems, access controls including multi-factor authentication, vulnerability scanning, penetration testing, independent third-party control audits, an internal bug bounty program, and other systems and processes.
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
Experience:
Our Director DevSecOps, Mr. Mohit Kumar, is a seasoned technology leader with over 15 years of experience in DevOps, SRE, Cloud Computing, and Cybersecurity. As the Deputy Director of DevOps and Cybersecurity at Zoomcar, Mohit heads the DevSecOps team and has led transformative projects, cultivated cybersecurity awareness and promoting holistic cybersecurity practices that were aligned with policies defined and approved by management. Mohit and his team are dedicated to integrating security into development, ensuring robust cloud security, enforcing security policies, and driving shift-left practices with operational excellence at Zoomcar.
Vishal Ramrakhyani, our Head of Engineering, has over 14 years of experience as a seasoned technology leader and operator with expertise in application development, IT, cybersecurity, data protection and governance. He has been associated with Zoomcar for more than 8 years and has led strategic initiatives to build robust cybersecurity practices that align with long-term business objectives. Vishal has also worked with internal DevSecOps and external security consultants to build policies around disaster recovery and incident response keeping business continuity as the core objective. Before Zoomcar, Vishal worked as an engineering leader in multiple startups in India.
Cybersecurity Risks
While we dedicate significant efforts and resources to our cybersecurity program, we may be unable to successfully identify threats, prevent attacks, satisfactorily resolve cybersecurity incidents, or implement adequate mitigating controls. Recently, on June 9, 2025, we identified a cybersecurity incident involving unauthorized access to our information systems, which is described in our Current Report on Form 8-K filed with the SEC on June 13 2025 (the “Cybersecurity Incident”). We have not yet fully determined the materiality of the Cybersecurity Incident. Any breach of our network security and information systems or other cybersecurity-related incidents that results in, or may result in, the loss, theft or unauthorized disclosure of data, or any delay in determining the full extent of a potential breach, could have a material adverse impact on our business, results of operations, and financial condition, including harm to our reputation and brand, reduced demand for our solutions, time-consuming and expensive litigation, fines, penalties, and other damages. To date and except as otherwise may be noted in this Annual Report on Form 10-K, we do not believe that any cybersecurity threats, including as a result of any previous cybersecurity incidents have materially affected, or are reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition. For more information relating to cybersecurity risks and uncertainties, please see the risk factor entitled “Breaches and other types of security incidents of our networks or systems similar to the recent Cybersecurity Incident, or those of our third-party service providers, could negatively impact our business, our brand and reputation, our ability to retain existing Hosts and Guests and attract new Hosts and Guests, may cause us to incur significant liabilities and adversely affect our business, results of operations, financial condition, and future prospects.” in Part I, Item 1A, and other risk factors in this 10-K.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
Our Director DevSecOps, Mr. Mohit Kumar, is a seasoned technology leader with over 15 years of experience in DevOps, SRE, Cloud Computing, and Cybersecurity. As the Deputy Director of DevOps and Cybersecurity at Zoomcar, Mohit heads the DevSecOps team and has led transformative projects, cultivated cybersecurity awareness and promoting holistic cybersecurity practices that were aligned with policies defined and approved by management. Mohit and his team are dedicated to integrating security into development, ensuring robust cloud security, enforcing security policies, and driving shift-left practices with operational excellence at Zoomcar.
Vishal Ramrakhyani, our Head of Engineering, has over 14 years of experience as a seasoned technology leader and operator with expertise in application development, IT, cybersecurity, data protection and governance. He has been associated with Zoomcar for more than 8 years and has led strategic initiatives to build robust cybersecurity practices that align with long-term business objectives. Vishal has also worked with internal DevSecOps and external security consultants to build policies around disaster recovery and incident response keeping business continuity as the core objective. Before Zoomcar, Vishal worked as an engineering leader in multiple startups in India.
|Cybersecurity Risk Management Processes Integrated [Text Block]
|Mohit and his team are dedicated to integrating security into development, ensuring robust cloud security, enforcing security policies, and driving shift-left practices with operational excellence at Zoomcar.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|
Vishal Ramrakhyani, our Head of Engineering, has over 14 years of experience as a seasoned technology leader and operator with expertise in application development, IT, cybersecurity, data protection and governance. He has been associated with Zoomcar for more than 8 years and has led strategic initiatives to build robust cybersecurity practices that align with long-term business objectives. Vishal has also worked with internal DevSecOps and external security consultants to build policies around disaster recovery and incident response keeping business continuity as the core objective. Before Zoomcar, Vishal worked as an engineering leader in multiple startups in India.
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|We have not yet fully determined the materiality of the Cybersecurity Incident. Any breach of our network security and information systems or other cybersecurity-related incidents that results in, or may result in, the loss, theft or unauthorized disclosure of data, or any delay in determining the full extent of a potential breach, could have a material adverse impact on our business, results of operations, and financial condition, including harm to our reputation and brand, reduced demand for our solutions, time-consuming and expensive litigation, fines, penalties, and other damages. To date and except as otherwise may be noted in this Annual Report on Form 10-K, we do not believe that any cybersecurity threats, including as a result of any previous cybersecurity incidents have materially affected, or are reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition.
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef