COMPLIANCE & CONTROLS

INDIAN LEGAL
& REGULATORY FRAMEWORK

Control mapping — not a representation of guaranteed compliance

The mapping below describes technical controls implemented by QuantumBlue that support the listed legal and regulatory frameworks. It is not a representation that QuantumBlue itself guarantees statutory compliance or legal admissibility. QuantumBlue provides cryptographic integrity, provenance, metadata capture, access controls, and certificate-generation capabilities — the applicability and sufficiency of these controls for any specific legal purpose is a matter for qualified legal counsel.

Framework → Capability Mapping

BSA §63

Bharatiya Sakshya Adhiniyam, 2023 — Section 63

Electronic evidence + certificate workflow

SHA-256 evidence hashing, device metadata capture, chain-of-custody records, and BSA §63 certificate generation with production method, device particulars, and operating conditions.

IT Act §43

Information Technology Act, 2000 — Section 43

Access and data-integrity controls

Unauthorized access monitoring, data integrity verification, and tamper-evident logging. Cryptographic controls that support defenses against unauthorized access to computer systems and data.

IT Act §66

Information Technology Act, 2000 — Section 66

Security incident evidence

Computer-related offence evidence capture with cryptographic signatures, chain-of-custody integrity, and audit trails supporting incident response and investigation workflows.

IT Act §66C

Information Technology Act, 2000 — Section 66C

Authentication and identity controls

Identity verification, MFA enrollment, session management, and credential security controls. Role-based access control (RBAC) with audited permission enforcement.

IT Act §66E

Information Technology Act, 2000 — Section 66E

Sensitive-data protection

Privacy controls for personal and sensitive information — encryption at rest (AES-256-GCM), data classification, access logging, and restricted export capabilities for confidential data.

IT Act §72 / 72A

Information Technology Act, 2000 — Sections 72 & 72A

Confidentiality and information controls

Confidentiality protections for personal information, breach notification support, and controlled data handling with encryption and access controls aligned with information privacy obligations.

DPDP Framework

Digital Personal Data Protection Act, 2023 + Rules, 2025

Personal-data governance

Data classification, encryption at rest, retention enforcement, soft-delete and controlled deletion workflows, and access logging — designed to support personal-data governance obligations under the DPDP framework.

Technical Standards

FIPS 204
ML-DSA-65 (Dilithium3) — digital signatures
FIPS 203
ML-KEM-768 (Kyber768) — key encapsulation
RFC 3161
Trusted timestamping — proof of existence
Hybrid Signatures
ML-DSA-65 + Ed25519 — PQC migration with classical verification
SHA-256
Cryptographic hashing for evidence integrity
AES-256-GCM
Encryption at rest for classified data

QuantumBlue is a B2B SaaS platform and CLI for post-quantum cryptography and digital evidence integrity. The technical specification and API reference are available at /docs.