Security & Cryptographic Integrity
How Attestly protects institutional intellectual property, student identity, and examination credibility with payments-grade technical controls.
Defense-in-Depth Architecture
Comprehensive security controls implemented from edge CDN to sandboxed runtime kernels.
Bank-Grade Encryption
All traffic across attestly.in is strictly encrypted using TLS 1.3 with Perfect Forward Secrecy (PFS). Data at rest in relational databases and storage buckets is encrypted with AES-256 keys.
Cryptographic Certificate Attestation
Every digital certificate and credential issued on Attestly is sealed with a SHA-256 cryptographic digest. Employers and universities verify credentials instantly on public ledgers without exposing private student records.
Safe Exam Browser (SEB) Lockdown
Our proctored examination engine enforces strict OS-level kiosk restrictions. It locks clipboard operations, terminates remote assistance software, and blocks unauthorized auxiliary displays.
Ephemeral Container Isolation
Student code compiles within short-lived, gVisor/Docker sandboxed micro-containers with non-root privileges, strict CPU/memory limits, and isolated egress network namespaces.
Multi-Tenant Data Partitioning
Organizational data is strictly separated via Row-Level Security (RLS) and cryptographic tenant scoping. No university or company can access or inspect another tenancy's syllabi or student scores.
Compliance & Industry Certifications
Engineered to satisfy SOC-2 Type II trust principles, ISO/IEC 27001 information security controls, India's DPDPA 2023 guidelines, and FERPA educational confidentiality standards.
Vulnerability Disclosure & Bug Bounty
We welcome responsible disclosures from security researchers, academic faculty, and ethical hackers. If you discover a potential vulnerability across any attestly.in service or student container environment:
- Submit full technical reproduction details to security@attestly.in.
- Please provide reasonable time for remediation prior to any public disclosure.
- Do not attempt to alter, delete, or access another customer's data.