Security & Privacy

    Data Protection

    Technical policies safeguarding your voting data.

    1. Cryptographic & Storage Encryption

    We implement industry-standard cryptographic controls for data protection in transit and at rest.

    • Data at Rest: Database instances, automated backups, and storage volumes are encrypted at rest using managed cloud volume encryption (AWS KMS AES-256).
    • Data in Transit: All communications between client browsers and edge application servers are encrypted using modern Transport Layer Security (TLS 1.3 supported) with strict HTTPS enforcement.
    • Vote Hashes: Each cast vote undergoes SHA-256 hashing to generate an immutable digital digest linked to a verifiable Merkle audit ledger.

    2. Data Localisation (Servers in India)

    In adherence to the Reserve Bank of India (RBI) guidelines on payment data and the Digital Personal Data Protection Act, 2023, Vote India Secure strictly enforces data localisation.

    Primary Datacenter: Mumbai, Maharashtra (Tier 4)
    Disaster Recovery (DR) Site: Bengaluru, Karnataka (Tier 4)

    No personal data, authentication logs, or voting records are ever routed through or stored on servers outside the physical boundaries of the Republic of India.

    3. Retention Policy

    Under the Companies (Management and Administration) Rules, 2014, records of electronic voting must be maintained securely.

    • Statutory Retention: Voting records and scrutinizer reports are retained for the legally mandated period (typically 8 years from the date of the meeting, or as instructed by the client company).
    • Data Destruction: Upon expiry of the retention period, or upon written request from the corporate client terminating the contract, all personal data and voting records are cryptographically wiped (shredded) beyond recovery, and a certificate of destruction is issued.

    4. Breach Notification Process

    While we maintain rigorous security controls, we have a documented Incident Response Plan in the unlikely event of a data breach.

    If a breach affecting personal data occurs, we will:

    • Notify the affected corporate clients without undue delay (target SLA: within 6 hours of discovery).
    • Notify the Data Protection Board of India as mandated under the DPDP Act 2023.
    • Report the cybersecurity incident to CERT-In within 6 hours as per the April 2022 CERT-In directions.
    • Provide a detailed post-incident forensic report and remediation steps.

    5. CERT-In Compliance

    The Indian Computer Emergency Response Team (CERT-In) is the national nodal agency for responding to computer security incidents.

    • NTP Synchronization: All our servers sync their system clocks with the Network Time Protocol (NTP) servers provided by NIC or NPL, as mandated by CERT-In.
    • Audit Logging: We maintain comprehensive logs of all ICT systems for a rolling period of 180 days within Indian jurisdiction.
    • VAPT: We undergo regular Vulnerability Assessment and Penetration Testing (VAPT) conducted by CERT-In empaneled security auditors.