Security & Incident Response
1. Security architecture
The portal uses authenticated accounts, role-based access, client-scoped entitlements, controlled document workflows, account activation/deactivation, audit records and restricted storage operations. Database row-level security is used to enforce server-side access boundaries.
2. Authentication
Portal accounts are authenticated through the configured identity service. Access can be disabled when an account or client relationship is inactive. Users are expected to use strong, unique credentials and to report suspected credential compromise immediately.
3. Documents
Documents are processed through controlled upload and review workflows. Duplicate detection and client-scoped ownership controls are used to reduce accidental cross-client storage. Soft deletion and audit history are used where operational or legal traceability requires preservation of the record.
4. Logging and auditability
The application maintains audit records for material portal activity. Infrastructure, authentication and security logs must be retained and protected according to applicable CERT-In directions and KKA's operational retention schedule. Application audit history must not be treated as a substitute for infrastructure/security logs.
5. Incident response
KKA will assess suspected security incidents, contain affected access where appropriate, preserve relevant evidence and coordinate with service providers and competent authorities. Cyber incidents that fall within applicable CERT-In reporting requirements are to be reported within the prescribed timeframe, including the applicable six-hour reporting requirement.
6. User reporting
If you suspect unauthorised access, an incorrect client association, accidental disclosure, credential compromise or other security issue, contact KKA through its established official communication channel as soon as possible. Please do not include unnecessary sensitive information in an initial report.
7. Operational controls
- least-privilege role and client access;
- server-side authorization and database policies;
- controlled storage integrations;
- auditability of material portal operations;
- secure session handling and account lifecycle controls; and
- backup, recovery and incident-response procedures appropriate to the service.