सुरक्षा
अवलोकन
Neotask को सुरक्षा को एक core principle के रूप में बनाया गया है। license activation से लेकर data storage से लेकर network communication तक हर layer, आपके डेटा की सुरक्षा और unauthorized access रोकने के लिए designed है।
License सुरक्षा
- Device Binding: प्रत्येक license SHA-256 fingerprint के माध्यम से cryptographically single device से bound है।
- HMAC-SHA256 Request Signing: सभी API requests per-device secret, nonce और timestamp के साथ signed हैं।
- Timing-Safe Comparison: सभी secret comparisons timing attacks रोकने के लिए constant-time algorithms का उपयोग करती हैं।
- Token Lifecycle: Access और refresh token expiry server-side को signed JWT claims के माध्यम से controlled है, जो instant revocation सक्षम करता है।
- Automatic Revalidation: आपकी license हर 6 घंटे में check की जाती है।
- Offline Grace Period: revalidation आवश्यक होने से पहले 72 घंटे का offline access।
- Remote Revocation: Licenses को server-side instantly revoke किया जा सकता है।
Two-Factor Authentication (TOTP)
Neotask dashboard access के लिए optional (लेकिन recommended) two-factor authentication का समर्थन करता है।
- Google Authenticator, Authy, 1Password, और किसी भी TOTP-compatible app के साथ compatible।
- Backup codes setup के दौरान प्रदान किए जाते हैं। ये codes SHA-256 hashed और one-time use only हैं।
- TOTP को आपके dashboard settings में Security section से किसी भी समय enable या disable किया जा सकता है।
Encryption
Data at Rest
- AES-256-GCM: सभी tokens, secrets और API keys rest में encrypted हैं।
- Machine-Derived Keys: Encryption keys आपकी device identity से scrypt के माध्यम से derived हैं।
- No Plaintext Storage: Tokens कभी plaintext में stored नहीं होते।
Data in Transit
- TLS 1.3: सभी API communication HTTPS पर travel करती है।
- WebSocket Secure (WSS): Real-time gateway communication encrypted है।
- HMAC Signing: प्रत्येक request में nonce और timestamp signature शामिल है।
Environment Secrets
- Two-Layer Encryption: Build-time environment encryption अलग keys का उपयोग करती है।
- No Hardcoded Secrets: Source code में zero API keys या tokens मौजूद हैं।
- Log Redaction: Sensitive data automatically logs से stripped होता है।
Desktop App Security
Electron Hardening
Neotask desktop application की सुरक्षा के लिए strict Electron security settings apply करता है:
sandbox: true, renderer process sandboxed environment में चलती है।contextIsolation: true, UI से main process तक direct access नहीं।nodeIntegration: false, UI को कोई Node.js APIs exposed नहीं हैं।webSecurity: true, Same-origin policy enforced है।
Content Security Policy (CSP)
default-src 'self', केवल app से ही resources load होते हैं।script-src 'self', कोई external scripts permitted नहीं हैं।- Popup windows blocked हैं।
- Navigation redirect attacks रोकने के लिए blocked है।
- State manipulation रोकने के लिए Page reload blocked है।
App Integrity
- ASAR Integrity: packaged app का SHA-256 hash verification।
- Version Attestation: kill switch capability के साथ server-signed manifest।
- Code Obfuscation: Production builds में JavaScript obfuscation apply होती है।
- Hard Fail Mode: App किसी भी integrity failure पर पूरी तरह block हो जाता है।
Network Security
Gateway Isolation
- Gateway loopback only (127.0.0.1) पर चलता है, जिसका अर्थ है zero external network exposure।
- आपकी machine के बाहर से कोई incoming connections accept नहीं की जाती।
- Session grants की 10-minute lifetime है, device-bound हैं और HMAC-signed हैं।
3-Strike Lockout
- 3 consecutive gateway operation failures के बाद, सभी operations blocked हो जाते हैं।
- Access restore करने के लिए manual reset आवश्यक है।
- यह mechanism brute-force attempts रोकता है।
API Security
Authentication Methods
| Method | Used For | Security Level |
|---|---|---|
| JWT Bearer Token | Web dashboard, API calls | Standard (90-day expiry) |
| License HMAC | Desktop app operations | High (per-device secret) |
| Session Grants | Gateway operations | Very High (10-min, HMAC-signed) |
| TOTP | Dashboard login | Additional factor |
Rate Limiting
| Endpoint | सीमा |
|---|---|
| Contact form | 15 मिनट में 5 requests |
| Login attempts | 15 मिनट में 10 requests |
| Analytics/tracking | 60 seconds में 30 requests |
Input Validation
- सभी IPC parameters को processing से पहले validate किया जाता है।
- सभी API inputs sanitized हैं।
- SQL injection, XSS और command injection के विरुद्ध protections मौजूद हैं।
Provider Key Security (BYOK)
Bring Your Own Key (BYOK) mode का उपयोग करते समय, Neotask आपकी API keys पर additional safeguards apply करता है:
- API keys को storage से पहले AES-256-GCM से encrypted किया जाता है।
- Keys कभी logged या error messages में exposed नहीं होती।
- Dashboard में masked form में keys प्रदर्शित की जाती हैं (केवल अंतिम 4 characters visible हैं)।
- Key remove करने पर Secure deletion की जाती है।
Safe Mode
Neotask में एक Safe Mode feature है जो agents के लिए execution sandbox प्रदान करता है:
- Per-agent execution sandbox प्रत्येक agent के operations को isolate करता है।
- Sensitive operations proceed करने से पहले explicit user approval की आवश्यकता होती है।
- एक master toggle आपको Safe Mode globally enable या disable करने की अनुमति देता है।
- Temporary changes के बाद Safe Mode को reactivate करने के लिए Schedule पर auto-re-enable।
- Real-time policy synchronization सभी connections में settings को consistent रखती है।
Audit और Compliance
- सभी configuration changes को timestamps के साथ logged किया जाता है।
- Config hashing unauthorized modifications detect करता है।
- Usage telemetry (opt-in) anomaly detection सक्षम करता है।
- CORS केवल authorized domains तक restricted है।
- सभी web responses पर Helmet security headers apply होते हैं।
Best Practices
- Two-factor authentication के लिए अपने dashboard पर TOTP enable करें।
- Backup codes download करें और उन्हें सुरक्षित रूप से store करें।
- अप्रत्याशित charges रोकने के लिए Daily budgets सेट करें।
- अपनी API keys पर पूर्ण control चाहते हैं तो BYOK mode का उपयोग करें।
- App updated रखें, auto-updates में security patches शामिल हैं।
- Safe Mode settings में periodically agent permissions review करें।