At TapDID (operated by DeccanIDentity), security is built into every layer—from hardware NFC chip locking to TLS 1.3 transit encryption and DPDP Act 2023 compliance.
Last Updated: August 2026 | Version 3.4
1. Security Architecture Overview
The TapDID Identity Platform is designed with a defense-in-depth framework. Whether an individual taps a smart card, scans a dynamic QR code, or manages profile details via our web portal, all interactions are secured using zero-trust cryptographic protocols.
Zero-Trust Guarantee: We never store plain-text credentials, financial PINs, or raw bank details. All sensitive user data is tokenized and stored in encrypted vaults backed by hardware security modules (HSM).
Password Lock Protection: Every TapDID card chip is permanently write-locked with a unique 32-bit hardware password key to prevent unauthorized chip tampering or overwriting.
7-Byte Unique ID (UID): Each IC features an immutable, factory-programmed 7-byte UID that acts as an unforgeable physical signature.
Anti-Cloning Integrity: Duplicate or cloned NFC chips are automatically detected and blocked by our cloud authentication servers upon tap.
3. Data in Transit Encryption (TLS 1.3 & HTTPS)
All web communications between your browser, phone tap, and TapDID servers are encrypted in transit using Transport Layer Security (TLS 1.3) and 256-bit SSL certificates.
HSTS Enforcement: HTTP Strict Transport Security (HSTS) is enabled to force secure HTTPS connections exclusively.
PFS (Perfect Forward Secrecy): Session keys are ephemeral, ensuring that even if a future key were compromised, past encrypted sessions remain secure.
4. Data at Rest Encryption (AES-256-GCM)
User profile database records, VCF contact details, custom card design parameters, and account settings are encrypted at rest using AES-256-GCM (Advanced Encryption Standard).
Passwords and authentication credentials are hashed using key-stretching functions (Argon2id / bcrypt) with individual cryptographic salts.
5. Dynamic QR Code Integrity & Anti-Tampering
TapDID dynamic QR codes and UPI payment links undergo continuous payload validation to prevent URL redirection attacks, phishing, or unauthorized payment link hijacking.
Dynamic Link Sanitization: All user-configured destination links are scanned against global malicious URL blacklists before activation.
Real-time Toggle: Profile owners can instantly lock, disable, or redirect their NFC card profile in real-time if their physical card is lost or stolen.
6. Regulatory Compliance & DPDP Act 2023
TapDID strictly adheres to the Digital Personal Data Protection (DPDP) Act 2023 of India, Information Technology Act 2000 (Section 43A), and international data privacy principles.
Data Minimization: We only collect data required to render your digital profile and process card orders.
Right to Erase: Users hold full authority to wipe their profile data permanently from our servers at any time.
Data Sovereignty: Indian user data is hosted within secure tier-4 Indian cloud datacenters.
7. Cloud Infrastructure & DDoS Protection
Our web servers operate behind Cloudflare Enterprise Web Application Firewalls (WAF) providing real-time mitigation against Distributed Denial of Service (DDoS) attacks, automated bot abuse, and SQL injection attempts.
Automated daily encrypted backups and multi-region failover ensure 99.99% service availability.
8. Vulnerability Reporting & Security Support
We welcome responsible security research. If you discover a security vulnerability or have questions about our encryption standards, please contact our security desk: