Skip to content

Security Policy & Vulnerability Disclosure

Last Updated: August 24, 2026 | CERT-In & DPDP Compliant

1. Platform Security Infrastructure

Digivite.in incorporates multi-layered security controls to protect invitation websites, guestbook messages, and host credentials:

  • Encrypted Authentication: User passwords are secured using salted bcrypt hashing algorithms. Plaintext passwords are never stored or logged.
  • Strict CSRF Tokens: All administrative and form requests require per-session cryptographically secure CSRF validation.
  • Input Sanitization: Prepared SQL PDO statements protect against SQL injection, and strict output escaping mitigates Cross-Site Scripting (XSS).
  • Isolated Media Uploads: User-uploaded files are stored in restricted directories with script execution strictly disabled.

2. Centralized Error & Incident Monitoring

Our application runtime features internal error monitoring that captures system exceptions and alerts our engineering team in real time without exposing sensitive customer data or credentials.

3. Responsible Vulnerability Disclosure

We welcome vulnerability reports from independent ethical security researchers across India and globally:

A. Guidelines for Researchers

  • Do not disrupt services or execute Distributed Denial of Service (DDoS) tests.
  • Do not modify, destroy, or exfiltrate customer personal data.
  • Provide a detailed proof of concept and reproduction steps when submitting your report.

B. Reporting Channel

Digivite Security Team

Phone: +91 7558840744

Instagram: @digivite.in_

Support Portal: digivite.in/contact

4. Indian Statutory Incident Reporting

In accordance with directions issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Information Technology Act, 2000, cybersecurity incidents are reported to CERT-In within mandated statutory timelines.