Subhadra is a direct benefit transfer scheme, which means the platform holds the identity and bank details of roughly one crore women and moves money against them. The consequence of a failure here is not reputational. It is a citizen who does not receive a payment she is entitled to, or whose identity is used somewhere she will never find out about.
What the brief actually was
The department needed the platform assessed before enrolment opened, remediated inside the delivery timeline, and evidenced in a form that would satisfy a CERT-In empanelled audit. Those three things pull against each other, and the sequencing is what makes or breaks the engagement.
Where we concentrated
On a scheme platform, authorisation is where the real risk sits. Authentication tends to be reasonably built because it is visible. Authorisation between roles, between districts, between a block level operator and a state level administrator, is where the gaps hide, because it is enforced in dozens of places and only has to be missed once.
We tested every role against every other role's data, by hand. Automated tooling does not find horizontal authorisation flaws reliably, because it does not know that beneficiary 4,00,112 and beneficiary 4,00,113 belong to different people.
The second area was the integration surface. A scheme of this kind talks to identity services, to banking rails and to departmental systems, and each integration is a trust boundary that somebody drew quickly under delivery pressure.
How remediation ran
We worked alongside the department's development team through the fix cycle rather than handing over a report and leaving. Every finding was retested after the fix, which is where a meaningful proportion of remediation turns out to be partial: the specific case in the report is closed and the class of issue remains open two endpoints away.
Retesting is not billed separately on our engagements, and this is why. A report describing a vulnerability that is still present is not a deliverable.
What was handed over
A findings report with reproduction steps, an executive summary written for the department's leadership rather than for engineers, a remediation tracker, and the evidence pack an auditor would ask for.













