SECURITY ARCHITECTURE
Enterprise brands entrust VISUAL SHADOW with proprietary commercial telemetry, marketplace credentials, and mission-critical digital pipelines. This technical specification defines our defense-in-depth security architecture, compliant with Section 43A of the Information Technology Act, 2000 and the Indian Computer Emergency Response Team (CERT-In) Cyber Security Directions, 2022.
CRYPTOGRAPHIC SHIELD
Mandatory TLS 1.3 in transit with HSTS preloading and hardware-backed AES-256 rest encryption for stored data.
CERT-IN COMPLIANCE
Mandatory 6-hour cybersecurity incident reporting to CERT-In and 180-day secure audit log retention within India.
AI CONTAINMENT
Sandboxed inference containers, zero retention agreements, and prompt sanitizers preventing proprietary data exfiltration.
01CERT-In Cyber Security Directions (2022) Alignment
In compliance with Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000 issued by CERT-In:
Mandatory 6-Hour Incident Notification (Direction 2)
Any cybersecurity incident matching the statutory Annexure list (e.g. data breach, ransomware attack, unauthorized access to systems) is systematically reported to incident@cert-in.org.in within six (6) hours of confirmation.
180-Day Secure Log Retention (Direction 4)
All system access logs, firewall telemetries, application transaction events, and API gateway access records are retained for a rolling period of 180 consecutive days within secure cloud infrastructure located in India.
Authoritative NTP Time Synchronization (Direction 1)
All production servers and network appliances synchronize system clocks with the National Physical Laboratory (NPL) and authorized National Informatics Centre (NIC) NTP servers.
02Defense-in-Depth Layering
We implement defense-in-depth across our consulting and software engineering footprint:
Global Anycast Edge CDN with automated L3/L4 DDoS mitigation, Web Application Firewall (WAF), and rate limiting.
Enforced TLS 1.3 with Perfect Forward Secrecy (ECDHE), strict HSTS headers, and SHA-256 certificate hashing.
OWASP Top 10 mitigation: strict Content Security Policy (CSP), anti-CSRF token validation, parameterized SQL, and HTML sanitization.
Zero cross-tenant database sharing; dedicated hardware-backed key vaults for API client secrets and credentials.
03Marketplace API Credentials & Least Privilege
When interfacing with Amazon Seller Central (SP-API), Shopify Admin APIs, or Meta Business Manager:
- Strict Delegated User Roles: We never request, accept, or store client master administrator credentials or bank withdrawal permissions. Access is limited to dedicated operational roles.
- Ephemeral Tokens: API keys and OAuth refresh tokens are stored in encrypted environment vaults with automated expiry schedules.
- Read-Only Auditing: Preliminary store audits are executed via read-only reporting permissions to prevent configuration alterations.
04AI Model Containment & Commercial Data Isolation
All inference requests to foundational language/vision models run under enterprise zero-retention agreements. Prompts are immediately purged post-computation.
Client catalogs, internal pricing formulas, and sales telemetry are never ingested into training corpuses for public AI models.
Bespoke AI brand ambassador weights operate inside isolated tenant containers with cryptographic hash verification.
Customer-facing AI agents employ semantic boundary checking and regex filters to prevent prompt injection attacks.
05Cybersecurity Incident Response & Responsible Disclosure
Pursuant to the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, our dedicated Security Operations Desk operates 24/7 for vulnerability disclosures:
Organization: VISUAL SHADOW
Operations Center: 6, J K Paul Road, Kolkata, 700038, Kolkata, 700038, West Bengal, India
Cybersecurity Hotline: +91 9073995531
Secure Disclosure Email: contact@visualshadow.com
CERT-In Statutory Reporting SLA: Within 6 hours of incident verification
Responsible security researchers submitting verified vulnerability reports will receive formal acknowledgment within 24 hours.
