Skip to main content

Government

Securing the data of one crore women under Subhadra Yojana

End-to-end security assessment and hardening of the citizen platform behind one of India's largest direct-benefit schemes for women.

Scale

1,00,00,000 beneficiaries

Government of Odisha

  • CERT-In Audit
  • Application Security Testing
  • Infrastructure
Securing the data of one crore women under Subhadra Yojana

The brief

Assess and harden the citizen platform behind Odisha's direct benefit scheme for women before enrolment opened at scale.

What we did

  • Full application and API assessment against OWASP ASVS
  • Authorisation testing across every beneficiary and administrative role
  • Infrastructure and configuration review of the hosting estate
  • CERT-In aligned reporting, remediation support and free retesting

Subhadra is a direct benefit transfer scheme, which means the platform holds the identity and bank details of roughly one crore women and moves money against them. The consequence of a failure here is not reputational. It is a citizen who does not receive a payment she is entitled to, or whose identity is used somewhere she will never find out about.

What the brief actually was

The department needed the platform assessed before enrolment opened, remediated inside the delivery timeline, and evidenced in a form that would satisfy a CERT-In empanelled audit. Those three things pull against each other, and the sequencing is what makes or breaks the engagement.

Where we concentrated

On a scheme platform, authorisation is where the real risk sits. Authentication tends to be reasonably built because it is visible. Authorisation between roles, between districts, between a block level operator and a state level administrator, is where the gaps hide, because it is enforced in dozens of places and only has to be missed once.

We tested every role against every other role's data, by hand. Automated tooling does not find horizontal authorisation flaws reliably, because it does not know that beneficiary 4,00,112 and beneficiary 4,00,113 belong to different people.

The second area was the integration surface. A scheme of this kind talks to identity services, to banking rails and to departmental systems, and each integration is a trust boundary that somebody drew quickly under delivery pressure.

How remediation ran

We worked alongside the department's development team through the fix cycle rather than handing over a report and leaving. Every finding was retested after the fix, which is where a meaningful proportion of remediation turns out to be partial: the specific case in the report is closed and the class of issue remains open two endpoints away.

Retesting is not billed separately on our engagements, and this is why. A report describing a vulnerability that is still present is not a deliverable.

What was handed over

A findings report with reproduction steps, an executive summary written for the department's leadership rather than for engineers, a remediation tracker, and the evidence pack an auditor would ask for.

Beneficiaries covered
1 crore
Assessment standard
OWASP ASVS, CERT-In aligned
Retesting
Included until closed

Engagement detail is summarised. Specific findings, payloads and architecture remain confidential under our client agreements.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.