Government of Punjab · Punjab Information Technology Board

Operations

Security, Access & Integrations

Platform trust posture for PITB review. Production hardening requires infrastructure integration beyond this POC.

Illustrative posture

Platform uptime

99.87%

Open incidents

2

Open vulnerabilities

1

Admin users

5

Security & compliance control set

Proposed architecture for the production gateway. Items marked proposed or requiring integration are commitments, not achieved certifications — no PCI-DSS, ISO or PECA certification is claimed by this POC.

Control areaProposed approachPOC status
Role-based access control (RBAC)Least-privilege roles per persona with permission matrix; enforced server-side on every action.Demonstrated in POC
Multi-factor authentication (MFA)TOTP/SMS second factor mandatory for all operator and finance accounts.Proposed for production
SSL/TLS in transitTLS 1.3 only, HSTS, forward secrecy, automated certificate rotation.Requires production integration
PCI-DSS payment approachNo card data touches the platform — redirect/hosted-fields tokenisation via a PCI-DSS certified PSP; platform stays SAQ-A scope.Proposed for production
PECA 2016 complianceLawful-interception request workflow, takedown and grievance handling, data-retention schedule aligned to PECA and PTA directives.Proposed for production
Encryption at restAES-256 volume and database encryption; KMS-held keys; field-level encryption for CNIC, IBAN and contact data.Requires production integration
Audit loggingAppend-only audit trail of every privileged action with actor, timestamp and reference — visible in Audit & System Settings.Demonstrated in POC
Breach notificationDocumented incident-response runbook with severity matrix and notification to PITB and affected users within 72 hours.Proposed for production
Backup & disaster recoveryHourly incremental / nightly full backups, 35-day encrypted retention, warm standby with 15-minute RPO and 2-hour RTO.Simulated in POC
Vulnerability assessmentContinuous dependency and container scanning plus quarterly authenticated VA with tracked remediation SLAs.Simulated in POC
Penetration testingIndependent third-party application and infrastructure penetration test before go-live and annually thereafter.Requires production integration

Security controls

  • Multi-factor authenticationUI demonstrated (simulated challenge)TOTP and SMS second factor for all seller, operations and executive accounts.
  • TLS / SSLRequires production integrationTLS 1.3 only, HSTS preload, automated certificate rotation.
  • Card data handlingSimulated payment step onlyNo card data stored; tokenised redirect to a PCI-DSS compliant acquirer.
  • PECA 2016 alignmentPolicy screens demonstratedData localisation, lawful access logging, takedown workflow for prohibited goods.
  • Backup & disaster recoveryRunbook summary demonstratedHourly incremental, daily full, cross-site replica; RPO 15 min / RTO 2 h.
  • Vulnerability managementRegister demonstrated with sample findingsQuarterly VAPT, monthly dependency scans, 15-day critical patch SLA.
  • Incident responseIncident log demonstratedSEV1–SEV3 matrix, 30-minute notification, published RCA within 5 working days.

Role-based access control

UserRoleScopeMFA
Hina RaufMarketplace Operations LeadKYC, catalogue, supportEnabled
Adeel ChaudhrySupport Agent (Tier 1)Tickets, returnsEnabled
Sundas RiazCatalogue ModeratorListings onlyEnabled
Faisal NadeemFinance OfficerSettlements, refundsEnabled
Dr. Kamran ShahidPITB Executive (read-only)Dashboards, reportsEnabled

Incident log

  • Checkout latency spike during Azadi SaleSEV2

    INC-1041 · opened 2026-08-01 20:10 · 42 min · Checkout p95 above 4s for 8% of sessions

    RCA: Connection pool saturation; pool size increased and cache warmed.

  • Courier webhook backlog (Leopards)SEV3

    INC-1046 · opened 2026-08-03 07:45 · 3 h 20 m · Tracking updates delayed for 1,240 consignments

    RCA: Upstream partner queue outage; retry backoff added.

  • SMS OTP delivery failures to one operatorSEV2

    INC-1049 · opened 2026-08-04 11:02 · Ongoing · OTP delivery success down to 82% on one network

    RCA: Under investigation with SMS aggregator.

  • Settlement batch reconciliation mismatchSEV1

    INC-1032 · opened 2026-06-28 02:15 · 5 h 05 m · PKR 1.42M in payouts held for one cycle

    RCA: COD remittance file duplicate rows; idempotency key added.

Vulnerability register

IDTitleSeverityStatusOwner
VLN-201Outdated image-processing dependencyHighPatchedPlatform
VLN-208Missing rate limit on search endpointMediumIn progressPlatform
VLN-214Verbose error messages in seller APILowOpenMarketplace

Integration status

External systems required before production go-live.

  • Payment gateway (1LINK / PayFast)SimulatedPayments
  • SMS aggregatorSimulatedMessaging
  • Courier APIs (TCS, Leopards, M&P, Trax)SimulatedLogistics
  • Email serviceSimulatedMessaging
  • FBR / PRA tax verificationRequires production integrationIdentity
  • NADRA CNIC verificationRequires production integrationIdentity
  • ERP connector (SAP / Oracle)Requires production integrationEnterprise
  • CRM connectorRequires production integrationEnterprise
  • POS / retail store syncRequires production integrationEnterprise
  • Identity SSO (PITB e-Khidmat)Requires production integrationIdentity

Backup, DR & continuity

Backup frequency
Hourly incremental, nightly full
Retention
35 days, encrypted at rest
RPO target
15 minutes
RTO target
2 hours
DR site
Secondary region, warm standby
Last drill
2026-06-28 — passed