Security
Overview
Neotask security ko core principle ke roop mein banaaya gaya hai. License activation se lekar data storage aur network communication tak -- har layer aapke data ki suraksha aur unauthorized access ko rokne ke liye design ki gayi hai.
License Security
- Device Binding: Har license SHA-256 fingerprint ke madhyam se ek device se cryptographically bound hoti hai.
- HMAC-SHA256 Request Signing: Sabhi API requests per-device secret, nonce aur timestamp ke saath signed hoti hain.
- Timing-Safe Comparison: Sabhi secret comparisons timing attacks rokne ke liye constant-time algorithms use karti hain.
- Token Lifecycle: Access aur refresh token expiry signed JWT claims ke madhyam se server-side control hoti hai, jisse instant revocation possible hai.
- Automatic Revalidation: Aapki license har 6 ghante check hoti hai.
- Offline Grace Period: Revalidation zaroori hone se pehle 72 ghante ka offline access.
- Remote Revocation: Licenses turant server-side revoke ho sakti hain.
Two-Factor Authentication (TOTP)
Neotask dashboard access ke liye optional (lekin recommended) two-factor authentication support karta hai.
- Google Authenticator, Authy, 1Password aur kisi bhi TOTP-compatible app ke saath compatible.
- Setup ke dauraan backup codes provide kiye jaate hain. Yeh codes SHA-256 hashed hain aur one-time use only hain.
- TOTP kabhi bhi aapke dashboard settings ke Security section se enable ya disable kiya ja sakta hai.
Encryption
Data at Rest
- AES-256-GCM: Sabhi tokens, secrets aur API keys rest par encrypted hain.
- Machine-Derived Keys: Encryption keys aapki device identity se scrypt ke madhyam se derive hoti hain.
- No Plaintext Storage: Tokens kabhi plaintext mein store nahi hote.
Data in Transit
- TLS 1.3: Sabhi API communication HTTPS par hoti hai.
- WebSocket Secure (WSS): Real-time gateway communication encrypted hai.
- HMAC Signing: Har request mein nonce aur timestamp signature shamil hoti hai.
Environment Secrets
- Two-Layer Encryption: Build-time environment encryption alag keys use karti hai.
- No Hardcoded Secrets: Source code mein zero API keys ya tokens hain.
- Log Redaction: Sensitive data logs se automatically strip hota hai.
Desktop App Security
Electron Hardening
Neotask desktop application ki suraksha ke liye strict Electron security settings laagu karta hai:
sandbox: true: Renderer process sandboxed environment mein chalta hai.contextIsolation: true: UI se main process tak koi direct access nahi.nodeIntegration: false: UI ko koi Node.js APIs expose nahi hote.webSecurity: true: Same-origin policy enforced hai.
Content Security Policy (CSP)
default-src 'self': Sirf app ke apne resources load hote hain.script-src 'self': Koi external scripts allowed nahi hain.- Popup windows blocked hain.
- Redirect attacks rokne ke liye navigation blocked hai.
- State manipulation rokne ke liye page reload blocked hai.
App Integrity
- ASAR Integrity: Packaged app ki SHA-256 hash verification.
- Version Attestation: Kill switch capability ke saath server-signed manifest.
- Code Obfuscation: Production builds mein JavaScript obfuscation applied hai.
- Hard Fail Mode: Kisi bhi integrity failure par app poori tarah block ho jaata hai.
Network Security
Gateway Isolation
- Gateway sirf loopback (127.0.0.1) par chalta hai, matlab zero external network exposure hai.
- Aapki machine ke baahar se koi incoming connections accept nahi hote.
- Session grants ki 10-minute lifetime hai, device-bound hain aur HMAC-signed hain.
3-Strike Lockout
- 3 consecutive gateway operation failures ke baad, sabhi operations block ho jaate hain.
- Access restore karne ke liye manual reset zaroori hai.
- Yeh mechanism brute-force attempts rokta hai.
API Security
Authentication Methods
| Method | Used For | Security Level |
|---|---|---|
| JWT Bearer Token | Web dashboard, API calls | Standard (90-day expiry) |
| License HMAC | Desktop app operations | High (per-device secret) |
| Session Grants | Gateway operations | Very High (10-min, HMAC-signed) |
| TOTP | Dashboard login | Additional factor |
Rate Limiting
| Endpoint | Limit |
|---|---|
| Contact form | 15 minutes mein 5 requests |
| Login attempts | 15 minutes mein 10 requests |
| Analytics/tracking | 60 seconds mein 30 requests |
Input Validation
- Sabhi IPC parameters processing se pehle validate hote hain.
- Sabhi API inputs sanitize hote hain.
- SQL injection, XSS aur command injection ke khilaf suraksha hai.
Provider Key Security (BYOK)
Bring Your Own Key (BYOK) mode use karte waqt, Neotask aapki API keys par additional safeguards laagu karta hai:
- API keys storage se pehle AES-256-GCM se encrypt hoti hain.
- Keys kabhi log ya error messages mein expose nahi hoti.
- Dashboard mein keys masked form mein dikhti hain (sirf last 4 characters dikhte hain).
- Key remove karne par secure deletion perform hoti hai.
Safe Mode
Neotask mein Safe Mode feature hai jo agents ke liye execution sandbox pradaan karta hai:
- Per-agent execution sandbox har agent ke operations ko isolate karta hai.
- Sensitive operations aage badhne se pehle explicit user approval chahiye.
- Master toggle aapko Safe Mode globally enable ya disable karne deta hai.
- Auto-re-enable on schedule temporary changes ke baad Safe Mode ko reactivate karta hai.
- Real-time policy synchronization sabhi connections par settings consistent rakhti hai.
Audit aur Compliance
- Sabhi configuration changes timestamps ke saath logged hote hain.
- Config hashing unauthorized modifications detect karti hai.
- Usage telemetry (opt-in) anomaly detection enable karti hai.
- CORS sirf authorized domains tak restricted hai.
- Sabhi web responses par Helmet security headers applied hain.
Best Practices
- Two-factor authentication ke liye apne dashboard par TOTP enable karein.
- Backup codes download karein aur unhe securely store karein.
- Unexpected charges rokne ke liye daily budgets set karein.
- Apni API keys par poora control chahte hain toh BYOK mode use karein.
- App updated rakhein, kyunki auto-updates mein security patches shamil hain.
- Safe Mode settings mein periodically agent permissions review karein.