AWS S3 Presigned Vault
All investor identity documents (COI, PAS-3, PAN, Form ISR) are stored in encrypted AWS S3 buckets using short-lived presigned URLs to prevent unauthorized direct URL guessing.
TLS 1.3 & HSTS Enforced
Full-site SSL encryption with HTTP Strict Transport Security (HSTS) prevents man-in-the-middle attacks and enforces secure HTTPS connections across all endpoints.
VAPT & Audit Logging
Regular Vulnerability Assessment and Penetration Testing (VAPT) conducted by CERT-In empaneled auditors. Every administrative action is logged to an immutable audit ledger.
SEBI Cyber Resilience Framework Compliance
| Security Standard | Implementation Control | Audit Status |
|---|---|---|
| Multi-Factor Authentication (MFA) | Enforced TOTP / SMS OTP authentication for administrative logins | COMPLIANT |
| Data At Rest Encryption | AES-256 server-side encryption for PostgreSQL & AWS S3 object store | COMPLIANT |
| Role-Based Access Control (RBAC) | Strict separation between public investor view, client entity desk, and registry admin | COMPLIANT |
| Annual VAPT Certification | CERT-In certified third-party vulnerability audit executed annually | VERIFIED |
