# Security ## Overview Neotask security ko core principle ke roop mein banaaya gaya hai. License activation se lekar data storage aur network communication tak -- har layer aapke data ki suraksha aur unauthorized access ko rokne ke liye design ki gayi hai. ## License Security - **Device Binding**: Har license SHA-256 fingerprint ke madhyam se ek device se cryptographically bound hoti hai. - **HMAC-SHA256 Request Signing**: Sabhi API requests per-device secret, nonce aur timestamp ke saath signed hoti hain. - **Timing-Safe Comparison**: Sabhi secret comparisons timing attacks rokne ke liye constant-time algorithms use karti hain. - **Token Lifecycle**: Access aur refresh token expiry signed JWT claims ke madhyam se server-side control hoti hai, jisse instant revocation possible hai. - **Automatic Revalidation**: Aapki license har 6 ghante check hoti hai. - **Offline Grace Period**: Revalidation zaroori hone se pehle 72 ghante ka offline access. - **Remote Revocation**: Licenses turant server-side revoke ho sakti hain. ## Two-Factor Authentication (TOTP) Neotask dashboard access ke liye optional (lekin recommended) two-factor authentication support karta hai. - Google Authenticator, Authy, 1Password aur kisi bhi TOTP-compatible app ke saath compatible. - Setup ke dauraan backup codes provide kiye jaate hain. Yeh codes SHA-256 hashed hain aur one-time use only hain. - TOTP kabhi bhi aapke dashboard settings ke **Security** section se enable ya disable kiya ja sakta hai. ## Encryption ### Data at Rest - **AES-256-GCM**: Sabhi tokens, secrets aur API keys rest par encrypted hain. - **Machine-Derived Keys**: Encryption keys aapki device identity se scrypt ke madhyam se derive hoti hain. - **No Plaintext Storage**: Tokens kabhi plaintext mein store nahi hote. ### Data in Transit - **TLS 1.3**: Sabhi API communication HTTPS par hoti hai. - **WebSocket Secure (WSS)**: Real-time gateway communication encrypted hai. - **HMAC Signing**: Har request mein nonce aur timestamp signature shamil hoti hai. ### Environment Secrets - **Two-Layer Encryption**: Build-time environment encryption alag keys use karti hai. - **No Hardcoded Secrets**: Source code mein zero API keys ya tokens hain. - **Log Redaction**: Sensitive data logs se automatically strip hota hai. ## Desktop App Security ### Electron Hardening Neotask desktop application ki suraksha ke liye strict Electron security settings laagu karta hai: - `sandbox: true`: Renderer process sandboxed environment mein chalta hai. - `contextIsolation: true`: UI se main process tak koi direct access nahi. - `nodeIntegration: false`: UI ko koi Node.js APIs expose nahi hote. - `webSecurity: true`: Same-origin policy enforced hai. ### Content Security Policy (CSP) - `default-src 'self'`: Sirf app ke apne resources load hote hain. - `script-src 'self'`: Koi external scripts allowed nahi hain. - Popup windows blocked hain. - Redirect attacks rokne ke liye navigation blocked hai. - State manipulation rokne ke liye page reload blocked hai. ### App Integrity - **ASAR Integrity**: Packaged app ki SHA-256 hash verification. - **Version Attestation**: Kill switch capability ke saath server-signed manifest. - **Code Obfuscation**: Production builds mein JavaScript obfuscation applied hai. - **Hard Fail Mode**: Kisi bhi integrity failure par app poori tarah block ho jaata hai. ## Network Security ### Gateway Isolation - Gateway sirf **loopback** (127.0.0.1) par chalta hai, matlab zero external network exposure hai. - Aapki machine ke baahar se koi incoming connections accept nahi hote. - Session grants ki 10-minute lifetime hai, device-bound hain aur HMAC-signed hain. ### 3-Strike Lockout - 3 consecutive gateway operation failures ke baad, sabhi operations block ho jaate hain. - Access restore karne ke liye manual reset zaroori hai. - Yeh mechanism brute-force attempts rokta hai. ## API Security ### Authentication Methods | Method | Used For | Security Level | |--------|----------|----------------| | **JWT Bearer Token** | Web dashboard, API calls | Standard (90-day expiry) | | **License HMAC** | Desktop app operations | High (per-device secret) | | **Session Grants** | Gateway operations | Very High (10-min, HMAC-signed) | | **TOTP** | Dashboard login | Additional factor | ### Rate Limiting | Endpoint | Limit | |----------|-------| | Contact form | 15 minutes mein 5 requests | | Login attempts | 15 minutes mein 10 requests | | Analytics/tracking | 60 seconds mein 30 requests | ### Input Validation - Sabhi IPC parameters processing se pehle validate hote hain. - Sabhi API inputs sanitize hote hain. - SQL injection, XSS aur command injection ke khilaf suraksha hai. ## Provider Key Security (BYOK) Bring Your Own Key (BYOK) mode use karte waqt, Neotask aapki API keys par additional safeguards laagu karta hai: - API keys storage se pehle AES-256-GCM se encrypt hoti hain. - Keys kabhi log ya error messages mein expose nahi hoti. - Dashboard mein keys masked form mein dikhti hain (sirf last 4 characters dikhte hain). - Key remove karne par secure deletion perform hoti hai. ## Safe Mode Neotask mein Safe Mode feature hai jo agents ke liye execution sandbox pradaan karta hai: - Per-agent execution sandbox har agent ke operations ko isolate karta hai. - Sensitive operations aage badhne se pehle explicit user approval chahiye. - Master toggle aapko Safe Mode globally enable ya disable karne deta hai. - Auto-re-enable on schedule temporary changes ke baad Safe Mode ko reactivate karta hai. - Real-time policy synchronization sabhi connections par settings consistent rakhti hai. ## Audit aur Compliance - Sabhi configuration changes timestamps ke saath logged hote hain. - Config hashing unauthorized modifications detect karti hai. - Usage telemetry (opt-in) anomaly detection enable karti hai. - CORS sirf authorized domains tak restricted hai. - Sabhi web responses par Helmet security headers applied hain. ## Best Practices 1. Two-factor authentication ke liye apne dashboard par **TOTP enable** karein. 2. **Backup codes download** karein aur unhe securely store karein. 3. Unexpected charges rokne ke liye **daily budgets set** karein. 4. Apni API keys par poora control chahte hain toh **BYOK mode use** karein. 5. **App updated rakhein**, kyunki auto-updates mein security patches shamil hain. 6. Safe Mode settings mein periodically **agent permissions review** karein.