Operations
Security, Access & Integrations
Platform trust posture for PITB review. Production hardening requires infrastructure integration beyond this POC.
Platform uptime
99.87%
Open incidents
2
Open vulnerabilities
1
Admin users
5
Security & compliance control set
Proposed architecture for the production gateway. Items marked proposed or requiring integration are commitments, not achieved certifications — no PCI-DSS, ISO or PECA certification is claimed by this POC.
| Control area | Proposed approach | POC status |
|---|---|---|
| Role-based access control (RBAC) | Least-privilege roles per persona with permission matrix; enforced server-side on every action. | Demonstrated in POC |
| Multi-factor authentication (MFA) | TOTP/SMS second factor mandatory for all operator and finance accounts. | Proposed for production |
| SSL/TLS in transit | TLS 1.3 only, HSTS, forward secrecy, automated certificate rotation. | Requires production integration |
| PCI-DSS payment approach | No card data touches the platform — redirect/hosted-fields tokenisation via a PCI-DSS certified PSP; platform stays SAQ-A scope. | Proposed for production |
| PECA 2016 compliance | Lawful-interception request workflow, takedown and grievance handling, data-retention schedule aligned to PECA and PTA directives. | Proposed for production |
| Encryption at rest | AES-256 volume and database encryption; KMS-held keys; field-level encryption for CNIC, IBAN and contact data. | Requires production integration |
| Audit logging | Append-only audit trail of every privileged action with actor, timestamp and reference — visible in Audit & System Settings. | Demonstrated in POC |
| Breach notification | Documented incident-response runbook with severity matrix and notification to PITB and affected users within 72 hours. | Proposed for production |
| Backup & disaster recovery | Hourly incremental / nightly full backups, 35-day encrypted retention, warm standby with 15-minute RPO and 2-hour RTO. | Simulated in POC |
| Vulnerability assessment | Continuous dependency and container scanning plus quarterly authenticated VA with tracked remediation SLAs. | Simulated in POC |
| Penetration testing | Independent third-party application and infrastructure penetration test before go-live and annually thereafter. | Requires production integration |
Security controls
- Multi-factor authenticationUI demonstrated (simulated challenge)TOTP and SMS second factor for all seller, operations and executive accounts.
- TLS / SSLRequires production integrationTLS 1.3 only, HSTS preload, automated certificate rotation.
- Card data handlingSimulated payment step onlyNo card data stored; tokenised redirect to a PCI-DSS compliant acquirer.
- PECA 2016 alignmentPolicy screens demonstratedData localisation, lawful access logging, takedown workflow for prohibited goods.
- Backup & disaster recoveryRunbook summary demonstratedHourly incremental, daily full, cross-site replica; RPO 15 min / RTO 2 h.
- Vulnerability managementRegister demonstrated with sample findingsQuarterly VAPT, monthly dependency scans, 15-day critical patch SLA.
- Incident responseIncident log demonstratedSEV1–SEV3 matrix, 30-minute notification, published RCA within 5 working days.
Role-based access control
| User | Role | Scope | MFA |
|---|---|---|---|
| Hina Rauf | Marketplace Operations Lead | KYC, catalogue, support | Enabled |
| Adeel Chaudhry | Support Agent (Tier 1) | Tickets, returns | Enabled |
| Sundas Riaz | Catalogue Moderator | Listings only | Enabled |
| Faisal Nadeem | Finance Officer | Settlements, refunds | Enabled |
| Dr. Kamran Shahid | PITB Executive (read-only) | Dashboards, reports | Enabled |
Incident log
- Checkout latency spike during Azadi SaleSEV2
INC-1041 · opened 2026-08-01 20:10 · 42 min · Checkout p95 above 4s for 8% of sessions
RCA: Connection pool saturation; pool size increased and cache warmed.
- Courier webhook backlog (Leopards)SEV3
INC-1046 · opened 2026-08-03 07:45 · 3 h 20 m · Tracking updates delayed for 1,240 consignments
RCA: Upstream partner queue outage; retry backoff added.
- SMS OTP delivery failures to one operatorSEV2
INC-1049 · opened 2026-08-04 11:02 · Ongoing · OTP delivery success down to 82% on one network
RCA: Under investigation with SMS aggregator.
- Settlement batch reconciliation mismatchSEV1
INC-1032 · opened 2026-06-28 02:15 · 5 h 05 m · PKR 1.42M in payouts held for one cycle
RCA: COD remittance file duplicate rows; idempotency key added.
Vulnerability register
| ID | Title | Severity | Status | Owner |
|---|---|---|---|---|
| VLN-201 | Outdated image-processing dependency | High | Patched | Platform |
| VLN-208 | Missing rate limit on search endpoint | Medium | In progress | Platform |
| VLN-214 | Verbose error messages in seller API | Low | Open | Marketplace |
Integration status
External systems required before production go-live.
- Payment gateway (1LINK / PayFast)SimulatedPayments
- SMS aggregatorSimulatedMessaging
- Courier APIs (TCS, Leopards, M&P, Trax)SimulatedLogistics
- Email serviceSimulatedMessaging
- FBR / PRA tax verificationRequires production integrationIdentity
- NADRA CNIC verificationRequires production integrationIdentity
- ERP connector (SAP / Oracle)Requires production integrationEnterprise
- CRM connectorRequires production integrationEnterprise
- POS / retail store syncRequires production integrationEnterprise
- Identity SSO (PITB e-Khidmat)Requires production integrationIdentity
Backup, DR & continuity
- Backup frequency
- Hourly incremental, nightly full
- Retention
- 35 days, encrypted at rest
- RPO target
- 15 minutes
- RTO target
- 2 hours
- DR site
- Secondary region, warm standby
- Last drill
- 2026-06-28 — passed