Website Security Policy
The official portal of Yantra India Limited is designed and hosted adhering to the comprehensive Cyber Security Guidelines prescribed by CERT-In and the Ministry of Defence, Government of India.
Security Architecture Safeguards
- HTTPS & Transport Encryption: End-to-end transport encryption utilizing modern TLS 1.3 protocols, strong cipher suites, and enforced HTTP Strict Transport Security (HSTS).
- Content Security Policy (CSP): Dynamic per-request cryptographic nonces and strict CSP headers preventing Cross-Site Scripting (XSS), clickjacking, and data injection.
- Multi-Factor Authentication (MFA): Time-based One-Time Password (TOTP / Google Authenticator) and session timeout restrictions enforced for all administrative roles.
- CERT-In Empaneled Security Audits: Periodic Vulnerability Assessment and Penetration Testing (VAPT) conducted by CERT-In certified auditors before production releases.