Privacy & Security Policy

ASTRA IETM • Cyber Security Department Association • grievance.astraietm.in

Confidentiality Guarantee

“Your Google account is used to verify that you are an authorized user and to help prevent fraudulent submissions. Your identity is stored securely but is not displayed to normal grievance reviewers. Identity information may only be accessed by authorized administrators when necessary and such access should be logged.”

1. Identity Verification via Google OAuth

To ensure the integrity of the grievance submission process and prevent automated spam or malicious reports, users authenticate using Sign-in with Google. Verification confirms membership within KMCT Institute of Engineering and Technology and the Cyber Security Department Association.

2. Server-Side Identity Isolation & Role Permissions

The platform strictly separates user identity from grievance content at the database and API authorization layers:

REVIEWER

Can view grievance details, update review status, add internal notes, and publish official responses. Identity remains strictly hidden.

ADMIN

Manages grievance assignments, review workflows, category configurations, and operational statistics. Identity remains strictly hidden.

SUPER_ADMIN

Full administrative oversight. May access complainant identity only when legitimately required, subject to mandatory justification logging.

3. Identity Access Audit Logging

Any attempt to view or export a complainant's identity details generates a permanent record in the IdentityAccessLog system table, recording the administrator ID, exact timestamp, and mandatory justification reason.

4. Technical Security Controls

  • HTTPS Transport Layer Encryption
  • HttpOnly, SameSite Session Cookies
  • Server-Side Authorization (Anti-IDOR)
  • File Upload Validation & MIME Sanitization
  • SQL Injection Protection (Prisma ORM)
  • Rate Limiting & Brute-Force Defense