Union Government, states, and public sector undertakings
Custody does not have to travel
Public records move between ministries, directorates, field and district offices, PSUs, bidders, contractors, consultants, auditors, and inquiry teams. A download or an email attachment can become a copy outside the departmental system.
Vaultize supports on-premises, private cloud, sovereign cloud, hosted, hybrid and air-gapped deployment designs with customer-controlled keys and data, so the record can move while custody stays with the institution. Deployment fit and references are confirmed during solution design.
government recordsPublic sector undertakingsRegulated workflowsSovereign deployment
Exposure signal
Where Public Record Risk Concentrates
Document exposure changes as citizen, tender, inter-department, PSU, and audit files move between offices, field units, bidders, contractors, and reviewers. Select a column to inspect the handoff risk it represents.
Illustrative exposure pattern, not live security telemetry
Selected threat
Citizen Records
Beneficiary lists, applications, and verification documents are exported for field checks and can outlive the task.
Protected and controlledElevated or exposed risk
The file is often the last mile
A Released Record Is A Separate Risk Decision
Identity, network, and application controls govern the systems that hold a public record. The exposure changes when a citizen file, tender document, note, or audit export is downloaded, forwarded, or retained outside that system.
This is a practical risk view. It is not a determination of regulatory applicability or compliance.
View the risk routeExpand full screen
Union and state government
Scope depends on the department and the processing
Section 8(5) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to protect personal data in its possession or under its control, including processing carried out on its behalf by a Data Processor, by taking reasonable security safeguards. Section 2 defines "person" to include the State, so a department can itself be a Data Fiduciary. The Schedule provides a penalty that may extend to two hundred and fifty crore rupees for breach of that obligation, as determined by the Board.
Section 17(2)(a) disapplies the Act to processing by such instrumentality of the State as the Central Government may notify, on the grounds listed there. That is a notified carve-out rather than a blanket exemption for government bodies, and the Section 17(1) exemptions expressly preserve sub-sections (1) and (5) of Section 8. Applicability should be assessed department by department.
The CERT-In Directions of 28 April 2022 name Government organisations alongside service providers, intermediaries, data centres, and body corporate, and require the cyber incidents listed in Annexure I to be reported within six hours of noticing them or being brought to notice about them.
The E-mail Policy of Government of India provides that only the e-mail services provided by NIC shall be used for official communications by all organizations except those exempted under its clause 14, and that services provided by other providers shall not be used for any official communication. It applies to employees of the Government of India and to State and Union Territory governments that use or adopt it.
The Guidelines for Indian Government Websites require a security audit clearance certificate from NIC, STQC, an STQC-empanelled laboratory, or a CERT-In empanelled laboratory before a government website, web application, portal, or mobile app is hosted in production, and require a Security Policy, Privacy Policy, and Contingency Management Plan approved by the department.
Public Sector Undertakings
Scope depends on the enterprise, the procurement, and the audit
Rule 160 of the General Financial Rules, 2017 makes it mandatory for Ministries and Departments to receive all bids through e-procurement portals in respect of all procurements, and Rule 159 makes e-publishing of tender enquiries, corrigenda, and bid awards mandatory for the Central Government, its attached and subordinate offices, and autonomous and statutory bodies, with narrow national-security exemptions.
Rule 149 of the General Financial Rules, 2017 records that the Government of India has established the Government e-Marketplace for common use goods and services, and that procurement by Ministries or Departments will be mandatory for goods or services available on GeM. The rules should be read with the current amendments for the entity concerned.
The Manual for Procurement of Goods, 2024, published by the Department of Expenditure and listed by the Central Vigilance Commission, states that the technical evaluation report is a confidential document whose contents shall not be disclosed, that all records relating to the evaluation shall be retained until completion of the project and its audit, and that the contractor shall maintain confidentiality and secrecy of the procuring entity's information.
The Department of Public Enterprises Guidelines on Corporate Governance for Central Public Sector Enterprises, continued on a mandatory basis, require board members and senior management to respect the confidentiality of information relating to the affairs of the company and to maintain the confidentiality of unpublished information about its business and affairs, and require the board to integrate risk management into normal business practice. These are governance duties rather than technical security standards.
The Comptroller and Auditor General's Report No. 15 of 2022 on Union Government compliance audit records that unauthorised use of user IDs and passwords by other postal staff or outsiders led to fraudulent withdrawal in four Circles, and recommends that an effective password policy be put in practice as part of an IT security policy to prevent unauthorised usage or login by staff.
Critical Information Infrastructure
Scope depends on notification as a protected system
By notification S.O. 18(E) of 16 January 2014, made under sub-section (1) of Section 70A of the Information Technology Act, 2000, the Central Government designated the National Critical Information Infrastructure Protection Centre as the national nodal agency in respect of Critical Information Infrastructure Protection.
The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 apply to organisations whose systems are notified under Section 70. They require the Chief Information Security Officer to share information security audit reports, post-audit compliance reports, and IT security service level agreements with NCIIPC, and to establish a process for sharing logs of the protected system.
The National Cyber Security Policy, 2013 states an objective to enable protection of information while in process, handling, storage, and transit, so as to safeguard privacy of citizen's data and reduce economic losses due to cyber crime or data theft. It is a policy statement, not a directly enforceable rule.
The CERT-In Directions of 28 April 2022 also require Government organisations to enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days within the Indian jurisdiction, and to synchronise system clocks with the NTP servers of NIC or NPL, or servers traceable to them.
MeitY has been empanelling cloud services of Cloud Service Providers since 2015 across public cloud, virtual private cloud, and government community cloud deployment models. The empanelment document requires that cloud services be hosted within India, that data residency be limited to the boundaries of India, and that no data, whether as backups or otherwise, be transmitted outside the boundaries and legal jurisdiction of India.
Ranked by public exposure
Priority Public Records
Swipe the wheel or tap a record class.Drag, scroll, click, or use the arrow keys to move between record classes without changing the layout.
Swipe or tapDrag or scroll01 / 05
Citizen
Tender
Notes
PSU
Audit
Citizen And Beneficiary Records
01
Privacy · entitlement integrity · public trust
Citizen And Beneficiary Records
01
Leak scenario
A beneficiary list, application pack, verification document, or grievance file is exported for a field check, an implementing agency, or a district office, and is retained after the underlying task is complete.
02
Common stopping point
Departmental applications, portals, and email gateways can control entry and transfer. An exported attachment becomes a separate copy with different storage, forwarding, and retention conditions.
03
Stronger practice
Classify the record, release it to a named recipient, set the permitted use and period, record activity, and withdraw access when the officer is transferred or the purpose closes.
04
Cost of inaction
Where the DPDP Act applies, Section 8(5) requires reasonable security safeguards and the Schedule provides a penalty that may extend to two hundred and fifty crore rupees for breach of that obligation. The CERT-In Directions of 28 April 2022 require Government organisations to report the listed incidents within six hours. In a reply laid before the Rajya Sabha on 31 March 2023, the Ministry of Electronics and Information Technology tabled CERT-In figures of 50 website hacking incidents of Central Ministries, Departments, and State Governments in 2022.
Operational risk map only. Regulatory scope depends on the department, entity, activity, record, and current instrument, and certain exemptions apply to the State and its instrumentalities. Linked government sources are authoritative. File controls support a wider governance, security, resilience, and response program; they do not establish compliance by themselves.
Operational risk map only. Regulatory scope depends on the department, entity, activity, record, and current instrument, and certain exemptions apply to the State and its instrumentalities. Linked government sources are authoritative. File controls support a wider governance, security, resilience, and response program; they do not establish compliance by themselves.
Documented Indian public sector incidents
The Record Is Already Public
Public-sector cyber incidents in India have already been placed on the record in written replies to Parliament, Press Information Bureau releases, and a listed PSU's own disclosure to the stock exchanges. In each case the Government or the entity itself put the facts in writing.
Two weeks
of manual working before restoration
Case 01
Operations Went Back To Paper
Case date
Cyber-attack in November 2022; answered in the Lok Sabha on 16 December 2022
The Ministry of Health and Family Welfare told the Lok Sabha that five physical servers of AIIMS, New Delhi, on which the e-Hospital application of NIC was hosted, were affected, and that a First Information Report numbered 349/22 had been registered by the institute with the Special Cell of Delhi Police. The reply records that no specific amount of ransom was demanded, though a message was discovered on the server suggesting that it was a cyber-attack.
What AIIMS New Delhi Faced
The same reply records that day-to-day operations, surgeries, associated activities, and record keeping were done in a manual mode. All e-Hospital data was retrieved from a backup server that was unaffected and restored on new servers, and most functions such as patient registration, appointment, admission, and discharge were restored after two weeks. A later reply of 21 July 2023 repeats those findings and records that a Security Command Centre was established at the institute.
Publicly documented incidents drawn from written replies to Parliament, Press Information Bureau releases, and the company's own stock-exchange filing. The organisations named are not represented as Vaultize customers, and no claim is made that Vaultize would have prevented these events. Dates, locations, leadership roles, figures, and consequences follow the linked primary sources; undisclosed locations are identified as not disclosed. Figures reported only in the press and not confirmed by a primary source are not stated here as fact, and matters recorded by different authorities are stated separately and are not combined.
A deliberate control trail
Make The Release Decision Reviewable
Use the file-level route as part of a broader departmental program. The objective is a clear answer to what was released, to whom, under what conditions, and what activity followed inside a deployment the institution controls.
Controlled record route
A concise record around a high-risk public exchange
ContextRecipientUseExpiryEventsCustody
01
Choose The Deployment First
Decide where the platform and the keys sit before the first file moves. Vaultize runs on-premises, in private cloud, sovereign cloud, hosted, hybrid, or air-gapped environments, with customer-controlled keys and data.
02
Define Priority Records
Start with the citizen, tender, inter-department, PSU contract, and audit files that leave the departmental system most often or create the largest confidentiality, integrity, or availability exposure.
03
Classify By Public Context
Connect the file to its sensitivity, custodian department, purpose, and route so the release decision reflects more than a generic document type.
04
Release To A Known Recipient
Apply the organisation's approved identity, access, and approval process before a high-risk record is shared with another office, a PSU, a bidder, a contractor, or a reviewer, with source-side encryption applied before the file leaves.
05
Bound Permitted Use
Set the relevant access, forwarding, printing, copying, and time conditions for the record and workflow, and withdraw access on transfer, superannuation, or closure of the purpose, subject to the organisation's policy and technical environment.
06
Retain Evidence For Review
Keep release, access, policy-change, revocation, and recovery evidence available to the responsible security, records, vigilance, audit, and incident teams.
Common public sector routes
Start Where Public Files Change Hands
Public records move from scheme intake through procurement, inter-department approval, PSU operations, audit and vigilance, and retention. The map shows where file-level control must remain connected as documents cross each handoff.
Government and PSU record lifecycleFour priority control points
01
Citizen And Scheme Records
Control beneficiary lists, applications, verification documents, and grievance files as they move between headquarters, field and district offices, and implementing agencies.
Purpose-bound citizen exchange
02
Tender And Procurement
Apply a bounded release route to estimates, bid documents, evaluation notes, and award files so confidentiality holds through the period when it matters most.
Accountable bidder access
03
Inter-Department Correspondence
Keep notes, references, and committee papers attributable while they move between ministries, departments, and attached and subordinate offices.
Traceable official routing
04
PSU Contractor And Audit Exchange
Define a controlled file route for vendors, project management consultants, site teams, statutory and internal auditors, and vigilance or inquiry officers handling PSU operating records.
Governed external handoff
Bring one record route
Make One Release Decision Reviewable
Walk through the records, recipients, permitted use, evidence, and deployment model a responsible department or PSU team can verify.