DPGNotes Legal
Home Legal Hub

Overview

  • Main Platform
  • Legal Summary Hub
  • Policy Updates

Standalone Policies

  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Advertising Policy
  • Legal Disclaimer
  • DRASA Regulations
  • Copyright Policy
  • DMCA Policy
  • Tracking & Analytics
  • Security Policy
  • Data Retention
  • External Links
Official Policy • DPDP Act 2023 & AdSense Compliant

DPGNotes Comprehensive Security Policy

Last Revised: September 2026 Reference: POL-DPG-SECU-2026-V3.2 Version: 3.2 (Comprehensive Edition)
Looking for a quick executive summary? Visit the Summary Version of this Policy in Legal Hub.

1. Defense-in-Depth Architecture & Security Charter

DPGNotes is dedicated to maintaining the absolute confidentiality, integrity, and availability of student academic notes, contributor credentials, and institutional resources. Operating under Akshat Network Hub, our technical architecture implements a rigorous Defense-in-Depth security methodology. We presume hostile network environments and enforce multi-layered cryptographic, transport, database, and client-side barriers against unauthorized access, data poisoning, credential theft, and denial-of-service disruptions.

This comprehensive Security Policy details our cryptographic protocols, cloud database access rules, vulnerability mitigation mechanisms, and ethical researcher disclosure guidelines in compliance with the Digital Personal Data Protection (DPDP) Act 2023 and guidelines of the Indian Computer Emergency Response Team (CERT-In).

TLS 1.3 & AES-256

Mandatory cryptographic forward secrecy across TLS 1.3 tunnels and hardware-accelerated AES-256 data volume encryption.

Granular Database Rules

Zero-trust cloud database security rules enforcing schema checks, role-based access, and strict client isolation.

Ethical VDP Program

Safe-harbor Vulnerability Disclosure Program welcoming collegiate cybersecurity researchers to report bugs responsibly.

2. Comprehensive Security Controls & Infrastructure Matrix

The matrix below outlines the specific security technologies and controls active across DPGNotes infrastructure:

Security Layer Core Technology / Standard Implementation Mechanism Threat Mitigated
Transport Encryption TLS 1.3 & TLS 1.2 with ECDHE Enforced HTTPS redirection, HSTS headers with preload max-age. Man-in-the-Middle (MitM) eavesdropping, packet sniffing.
Data at Rest Hardware-Accelerated AES-256 Cloud-managed key rotation on underlying persistent storage volumes. Physical disk theft, offline database extraction.
Client-Side Sanitization DOMPurify & Entity Encoding Strict output filtering on all note titles, subjects, and search parameters. Stored & Reflected Cross-Site Scripting (XSS).
HTTP Security Headers CSP, HSTS, X-Frame-Options: DENY Edge-level HTTP header injection on every response payload. Clickjacking, MIME sniffing, unauthorized script execution.
API & Quota Protection Token Bucket Rate Limiting Algorithmic burst throttling on generation and search endpoints. DDoS attacks, credential brute-forcing, scraper scraping.

3. Cloud Database Access Controls & Tenant Isolation

Our cloud data storage utilizes strictly configured access rules evaluated directly at the database engine level:

  • Zero Implicit Access: By default, all read and write operations from unauthenticated sources are denied unless explicitly matched against a public read rule for approved study notes.
  • Contributor Segregation: Contributors can only update or delete documents for which their cryptographically verified User UID matches the document's author metadata. Cross-tenant tampering is architecturally impossible.
  • Strict Field Schema Validation: Write requests to Cover Page Logs and Note collections must validate field type, character length constraints, and required fields (such as Subject Name, Subject Code, and Session). Requests containing unexpected keys or malformed JSON are immediately rejected.

4. Client-Side Integrity & Cross-Site Scripting (XSS) Prevention

To ensure student browsers are never compromised when reviewing community study documents, DPGNotes maintains uncompromising DOM hygiene:

  • Content Security Policy (CSP): Restricts script execution to vetted origin scripts and authorized CDN endpoints (Google Fonts, RemixIcon, and AdSense). Inline script injection is blocked.
  • Anti-Clickjacking Framing Controls: The platform sends X-Frame-Options: DENY and CSP frame-ancestors 'none' headers to prevent hostile websites from embedding DPGNotes inside malicious transparent iframes.
  • Secure Cookie Flags: All tracking and session tokens carry mandatory Secure, HttpOnly (where server-mediated), and SameSite=Lax or SameSite=Strict attributes to prevent cross-site request forgery (CSRF).

5. Rate Limiting, DDoS Mitigation & Edge Defense

Our content delivery network (CDN) edge incorporates automated threat analysis to defend against distributed denial-of-service (DDoS) events, brute-force dictionary attacks, and headless bot crawlers:

  • Generator Endpoint Throttling: Cover page generation endpoints enforce token-based daily quotas (1/day for guests, 3/day for contributors). Requests exceeding allowed burst velocity are met with HTTP 429 (Too Many Requests).
  • Search Query Caps: High-frequency automated search requests are subjected to temporary cryptographic challenges (CAPTCHA) to prevent database resource exhaustion.

6. Incident Response Plan (IRP) & Breach Notification Protocol

DPGNotes maintains a structured Incident Response Plan (IRP) governed by our core engineering team. In the event of a suspected cybersecurity incident or unauthorized data access:

  • Phase 1 — Identification & Triage: Anomaly detection triggers automated alerts to the Security Administrator within 15 minutes of occurrence.
  • Phase 2 — Containment & Isolation: Compromised endpoints or affected database paths are instantly quarantined at the firewall edge.
  • Phase 3 — Eradication & Patching: Vulnerability causes are diagnosed, patched in source control, and pushed through automated deployment pipelines.
  • Phase 4 — Statutory Reporting: In strict compliance with CERT-In directions and the DPDP Act 2023, significant cybersecurity incidents are notified to the Data Protection Board of India and affected users within 72 hours of formal confirmation.

7. Responsible Vulnerability Disclosure Program (VDP)

DPGNotes enthusiastically welcomes collegiate cybersecurity scholars, ethical penetration testers, and independent security researchers to participate in our Vulnerability Disclosure Program under full legal safe harbor:

  • Safe Harbor Guarantee: DPGNotes pledges not to initiate civil litigation or report researchers to cyber law enforcement under Section 43 of the Information Technology Act 2000, provided testing complies strictly with these guidelines.
  • In-Scope Testing: Web application business logic flaws, DOM-based XSS, server-side misconfigurations, and authentication bypasses on DPGNotes public endpoints.
  • Out-of-Scope Behaviors: Volumetric DDoS attacks, social engineering of student volunteers, physical intrusions, or unauthorized access to/alteration of another student's academic documents.
  • Reporting Protocol: Send a complete vulnerability report detailing reproduction steps, request logs, and proof-of-concept payloads to our Security Officer at its.akshatnetworkhub23@gmail.com.
  • SLA Commitment: Acknowledgement within 24 business hours; preliminary technical assessment within 72 hours.

Information Security & Vulnerability Desk

DPGNotes Cyber Operations & Platform Defense Team

Official Security Email: its.akshatnetworkhub23@gmail.com

Grievance & Security Ticket: Support & Security Escalation Portal

SLA Commitment: Vulnerability reports acknowledged within 24 hours.

Related Compliance Policies

Privacy Policy Data Retention DRASA Regulations Terms & Conditions