Independent concept prototype for Build What Moves India · Not a Government of India service · All data is demo data.

Security policy

What this prototype does to protect a sign-in, what a real deployment must add before it may host citizens, and how to tell us about a weakness.

Independent concept prototype. Every citizen, identifier and document here is synthetic; no live government system is called. This page is written in the form a government website's security policy takes, so the gaps are visible rather than hidden.

What is in place on this site

What a real deployment must add before hosting citizens

Contingency

The design assumes the hub will sometimes be down. Departments cache the hub's discovery document and keys, keep their own sessions, and fall back to their own sign-in with a visible notice. The authenticator works without signal. A real deployment adds the recovery-time and recovery-point targets of its business-continuity plan here.

Report a vulnerability

Tell us through the repository, and tell CERT-In: its Responsible Vulnerability Disclosure and Coordination Policy is India's official channel, at cert-in.org.in and vdisclose@cert-in.org.in. A machine-readable copy of this section is at /.well-known/security.txt.

Contact

Questions about this policy, or about the demonstration: see the Contact us page for the team and the repository.