कालदर्शीKAALADARSHI

SECURITY

Protecting a deeply personal experience.

This overview describes Kaaladarshi's security posture at a responsible, high level. It intentionally avoids publishing infrastructure details that could weaken protection.

Security approach

Kaaladarshi applies defense-in-depth principles across identity, sessions, application access, data handling, monitoring, software changes, and service operations. Safeguards are selected according to risk and may evolve without public disclosure of sensitive implementation details.

Account and session security

  • Federated sign-in reduces the need to create or store a separate Kaaladarshi password.
  • Session cookies are designed to be inaccessible to ordinary page scripts and configured according to the deployment environment.
  • Sessions may expire, be revoked, or require re-authentication when risk or inactivity warrants it.
  • Authentication and protected actions are validated by the server rather than trusted solely to the browser.

Data protection

Data minimization

Only information reasonably needed for product, security, analytics, and support purposes should be collected.

Transport protection

Production traffic is expected to use HTTPS so information is encrypted in transit.

Access restriction

Administrative and service access should be limited according to operational need.

Backups and recovery

Production data should be backed up and recoverability tested according to launch operations.

Secure operations

Operational practices include configuration separation, secret management, dependency updates, logging, abuse controls, error monitoring, backup planning, and review of production changes. Security events may be investigated and affected users notified when required by law or reasonably appropriate.

What you can do

  • Use an account you control and protect access to the associated identity provider.
  • Sign out on shared devices and avoid saving sensitive Life Maps in public or untrusted environments.
  • Do not share screenshots, readings, or linked-person data without considering the privacy of everyone involved.
  • Report suspicious activity and avoid clicking untrusted links claiming to represent Kaaladarshi.

Responsible disclosure

Security concerns should be submitted through the Contact page with enough detail to reproduce the issue safely. Do not access, alter, retain, or disclose another person's data; disrupt the service; use social engineering; or demand payment as a condition of withholding disclosure.

A dedicated security address may be published before public launch.