Security & Compliance Center

Security & Cryptographic Integrity

How Attestly protects institutional intellectual property, student identity, and examination credibility with payments-grade technical controls.

Defense-in-Depth Architecture

Comprehensive security controls implemented from edge CDN to sandboxed runtime kernels.

Bank-Grade Encryption

All traffic across attestly.in is strictly encrypted using TLS 1.3 with Perfect Forward Secrecy (PFS). Data at rest in relational databases and storage buckets is encrypted with AES-256 keys.

Cryptographic Certificate Attestation

Every digital certificate and credential issued on Attestly is sealed with a SHA-256 cryptographic digest. Employers and universities verify credentials instantly on public ledgers without exposing private student records.

Safe Exam Browser (SEB) Lockdown

Our proctored examination engine enforces strict OS-level kiosk restrictions. It locks clipboard operations, terminates remote assistance software, and blocks unauthorized auxiliary displays.

Ephemeral Container Isolation

Student code compiles within short-lived, gVisor/Docker sandboxed micro-containers with non-root privileges, strict CPU/memory limits, and isolated egress network namespaces.

Multi-Tenant Data Partitioning

Organizational data is strictly separated via Row-Level Security (RLS) and cryptographic tenant scoping. No university or company can access or inspect another tenancy's syllabi or student scores.

Compliance & Industry Certifications

Engineered to satisfy SOC-2 Type II trust principles, ISO/IEC 27001 information security controls, India's DPDPA 2023 guidelines, and FERPA educational confidentiality standards.

Vulnerability Disclosure & Bug Bounty

We welcome responsible disclosures from security researchers, academic faculty, and ethical hackers. If you discover a potential vulnerability across any attestly.in service or student container environment:

  • Submit full technical reproduction details to security@attestly.in.
  • Please provide reasonable time for remediation prior to any public disclosure.
  • Do not attempt to alter, delete, or access another customer's data.
Security Operations Center (SOC)
PGP Key available upon request • 24-hour initial triage SLA
security@attestly.in