INDIAN JURISDICTION // CERT-IN DIRECTIVES 2022 & IT ACT 2000

SECURITY ARCHITECTURE

Enterprise brands entrust VISUAL SHADOW with proprietary commercial telemetry, marketplace credentials, and mission-critical digital pipelines. This technical specification defines our defense-in-depth security architecture, compliant with Section 43A of the Information Technology Act, 2000 and the Indian Computer Emergency Response Team (CERT-In) Cyber Security Directions, 2022.

STATUTORY JURISDICTION: REPUBLIC OF INDIAREGULATORY ALIGNMENT: CERT-IN 2022 / SECTION 70BENCRYPTION STANDARD: TLS 1.3 / AES-256

CRYPTOGRAPHIC SHIELD

Mandatory TLS 1.3 in transit with HSTS preloading and hardware-backed AES-256 rest encryption for stored data.

CERT-IN COMPLIANCE

Mandatory 6-hour cybersecurity incident reporting to CERT-In and 180-day secure audit log retention within India.

AI CONTAINMENT

Sandboxed inference containers, zero retention agreements, and prompt sanitizers preventing proprietary data exfiltration.

01CERT-In Cyber Security Directions (2022) Alignment

In compliance with Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000 issued by CERT-In:

Mandatory 6-Hour Incident Notification (Direction 2)

Any cybersecurity incident matching the statutory Annexure list (e.g. data breach, ransomware attack, unauthorized access to systems) is systematically reported to incident@cert-in.org.in within six (6) hours of confirmation.

180-Day Secure Log Retention (Direction 4)

All system access logs, firewall telemetries, application transaction events, and API gateway access records are retained for a rolling period of 180 consecutive days within secure cloud infrastructure located in India.

Authoritative NTP Time Synchronization (Direction 1)

All production servers and network appliances synchronize system clocks with the National Physical Laboratory (NPL) and authorized National Informatics Centre (NIC) NTP servers.

02Defense-in-Depth Layering

We implement defense-in-depth across our consulting and software engineering footprint:

PERIMETER & EDGE

Global Anycast Edge CDN with automated L3/L4 DDoS mitigation, Web Application Firewall (WAF), and rate limiting.

TRANSPORT SECURITY

Enforced TLS 1.3 with Perfect Forward Secrecy (ECDHE), strict HSTS headers, and SHA-256 certificate hashing.

APPLICATION HARDENING

OWASP Top 10 mitigation: strict Content Security Policy (CSP), anti-CSRF token validation, parameterized SQL, and HTML sanitization.

TENANT DATA ISOLATION

Zero cross-tenant database sharing; dedicated hardware-backed key vaults for API client secrets and credentials.

03Marketplace API Credentials & Least Privilege

When interfacing with Amazon Seller Central (SP-API), Shopify Admin APIs, or Meta Business Manager:

  • Strict Delegated User Roles: We never request, accept, or store client master administrator credentials or bank withdrawal permissions. Access is limited to dedicated operational roles.
  • Ephemeral Tokens: API keys and OAuth refresh tokens are stored in encrypted environment vaults with automated expiry schedules.
  • Read-Only Auditing: Preliminary store audits are executed via read-only reporting permissions to prevent configuration alterations.

04AI Model Containment & Commercial Data Isolation

ZERO-RETENTION INFERENCE

All inference requests to foundational language/vision models run under enterprise zero-retention agreements. Prompts are immediately purged post-computation.

PROPRIETARY TRAINING BAN

Client catalogs, internal pricing formulas, and sales telemetry are never ingested into training corpuses for public AI models.

SYNTHETIC MODEL SANDBOXING

Bespoke AI brand ambassador weights operate inside isolated tenant containers with cryptographic hash verification.

DUAL-STAGE GUARDRAILS

Customer-facing AI agents employ semantic boundary checking and regex filters to prevent prompt injection attacks.

05Cybersecurity Incident Response & Responsible Disclosure

Pursuant to the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, our dedicated Security Operations Desk operates 24/7 for vulnerability disclosures:

SECURITY OPERATIONS & CERT-IN POINT OF CONTACT24/7 ACTIVE DESK

Organization: VISUAL SHADOW

Operations Center: 6, J K Paul Road, Kolkata, 700038, Kolkata, 700038, West Bengal, India

Cybersecurity Hotline: +91 9073995531

Secure Disclosure Email: contact@visualshadow.com

CERT-In Statutory Reporting SLA: Within 6 hours of incident verification

Responsible security researchers submitting verified vulnerability reports will receive formal acknowledgment within 24 hours.