SectorsChapter 15 · ಸೈಬರ್

The delivery layer of digital rights.

Five operating institutions tied to the Karnataka State Service Log (KSSL) — the cryptographic floor — plus Digital Public Infrastructure, the open public datasets, and the citizen technology layer that runs on top of the spine. Rights live in Vol I Ch 6; this chapter owns delivery.

Security is not an IT add-on. It is a governance guarantee. Karnataka State Service Log anchors every state digital interaction. The integrity of the log is no longer trust-in-the-administrator — it is mathematically detectable if any entry is altered after the fact.
KSSL
Karnataka State Service Log — cryptographic floor
CSOC
Cyber Security Operations Centre — 24/7, compel-patching
72h
incident disclosure rule from containment
PQC
post-quantum cryptography by default for new builds
Cybersecurity, DPI & Citizen Tech
ಸೈ
The problem we solve

The structural failures in Cybersecurity, DPI & Citizen Tech.

Digital governance expands the attack surface. Without serious cybersecurity, the operating spine becomes a single point of failure for fraud, identity theft, ransomware, and politically motivated leaks.

Inconsistent security posture

Karnataka's departments vary widely. Many run on outdated stacks with inconsistent patching and incident response.

Vendor + contractor weak links

Outsourcing the system does not outsource accountability for the breach. The vendor's bug becomes the citizen's data leak.

Resident-side awareness uneven

Digital exclusion compounds the security gap. A resident assisted by an unknown kiosk operator presents a different attack surface.

DPI under-utilised by departments

India Stack exists nationally; Karnataka hasn't built the operational layer that uses it consistently across departments.

Single-system silos

Identity, payments, signing, storage reinvented per department. Resident stuck navigating seams; integrity not detectable.

Security is not an IT add-on. It is a governance guarantee. Karnataka treats the cryptographic floor as durable infrastructure — like roads, not like software-as-a-service.

The architecture

Five operating institutions. One cryptographic floor.

KSSL is the single logging + anchoring layer. CSOC has compel-patching authority. Hardware Security Modules + threshold cryptography make bulk operations require multiple signoffs. Post-quantum cryptography by default.

1
State Security Operations Centre (SOC)
24/7, with MTTD + MTTC as published KPIs on Mission Control. Operational security for every state system.
H.145–H.149
2
Secure-by-design standards
Published, binding, audited. State systems + vendor procurement must meet the standard. Software Bill of Materials mandatory.
H.150–H.152
3
Consent-based data-access vault
Operating expression of the Citizen Data Trust's consent framework. Every cross-system flow requires a consent token.
H.153–H.155
4
Incident transparency + 72h disclosure
Every breach disclosed publicly within 72 hours of containment. Post-incident reports published within 30 days.
H.156–H.158
5
Cybercrime + digital literacy
Cybercrime response capacity + digital-literacy programmes for residents, kiosk operators, small businesses.
H.159–H.162
F
CSOC — apex statutory authority
Compel-patching authority across every state system. Audit access independent of the executive. Bug-bounty programme.
Vol I Ch 2
KSSL — the cryptographic floor
Single logging + anchoring layer. Every read, write, payment, AI decision, service hand-off passes through KSSL. Hashed, batched, anchored into publicly verifiable append-only structure. Built on open standards; published under open licence; reproducible by any party.
How it shows up for you

Three operating loops.

Three flows that define what the cryptographic floor means operationally — for a citizen, a developer, and an auditor.

Citizen — the access log on JANATA

See who accessed your data, live.

1

Every state system access to your data generates a KSSL entry.

2

Your JANATA Citizen role-card shows the access log live — accessing officer ID, records accessed, reason code.

3

Suspicious access? Raise a Grievance Justice Authority ticket from JANATA.

4

Break-glass override? You're notified within 24 hours; quarterly review panel audits the override.

Developer — the open-source spine

Karnataka's code is yours to audit.

1

State systems built under the open-source mandate (Karnataka State Digital Infrastructure Act).

2

Source code published; AI models open-sourced after a 2-year proprietary window.

3

Public verifier nodes can verify KSSL anchors without state permission.

4

Bug bounty triage time ≤24 hours median; reproducible builds for KSSL itself.

Auditor — verifiable transparency

Detect tampering mathematically.

1

Civil-society Independent Audit Board has standing to audit every state digital system.

2

Threshold cryptography means no single admin can do bulk damage; multiple keys required.

3

AI-Use Register lists every state AI with description, training data, performance, annual bias audit.

4

Independent witness co-signing of KSSL anchors — trust isn't concentrated in the executive.

Implementation roadmap

KSSL live in Year 1. Universal PQC adoption by Year 5.

The cryptographic floor is built once and runs forever. The hard work is structural — getting the floor right.

0–100 days
  • Karnataka State Service Log open-source reference implementation published
  • Karnataka Cyber Security + Citizen Consent Act tabled
  • CSOC interim leadership named; bug-bounty programme launch
  • Software Bill of Materials mandate published
Year 1
  • KSSL live across pilot high-stakes systems
  • PQC adoption on new builds 100% (procurement standard binding)
  • CSOC fully operational with compel-patching authority
  • Citizen Consent Ledger live in 3 sectors (Health, Education, Welfare)
Year 3
  • KSSL anchoring across every state digital service
  • CSOC mean-time-to-patch on compelled orders ≤72 hours
  • Citizen Consent Ledger revocation propagation ≤1 hour
  • Karnataka Open Data Portal coverage ≥5,000 datasets
Year 5
  • Streaming KSSL anchors with defined window
  • Bug-bounty triage time ≤24 hours median
  • Karnataka Open Data Portal coverage ≥10,000 datasets
  • Legacy systems on PQC migration plan with 15-year outer bound
Year 10
  • Karnataka's cryptographic floor exported as the open-source reference implementation for other Indian states
  • Independent witness network distributed across civil society
  • Anti-capture architecture culturally embedded in cadre training
  • PQC migration complete across inherited systems
Headline KPIs · live on the Open Ledger

Six numbers we publish every quarter.

Full set in Vol III App A. Each KPI has a published baseline, Year-1 target, Year-5 target — and where relevant, a Year-10 commitment.

≤24h
Bug-bounty triageMedian time to triage by Year 5
≤72h
CSOC patchMean-time-to-patch on compelled orders by Year 5
≤1h
Consent revocationCitizen Consent Ledger revocation propagation by Year 5
100%
PQC on new buildsProcurement standard binding from Year 1
≥10k
Open Data PortalDatasets published by Year 5
100%
Sensor SBOMSoftware Bill of Materials mandate enforced
Why this can't quietly be reversed

Why Cybersecurity, DPI & Citizen Tech can't quietly be reversed.

The cryptographic floor exists precisely to prevent quiet reversal. Six structural mechanisms enforce that.

KSSL anchors mathematically detect tampering

Trust is in the math, not the admin

Every entry hashed + batched + anchored into a publicly verifiable append-only structure. Altering an entry after the fact is mathematically detectable.

Threshold cryptography on bulk ops

No single admin can do mass damage

Hardware Security Modules + threshold cryptography mandatory for any bulk operation. No single administrator's keys are sufficient.

CSOC statutory + independent

Audit access not at executive discretion

CSOC has audit access independent of the executive. Cannot be quietly defunded or restructured; statutory.

Open-source mandate

State software published under public licence

Karnataka State Digital Infrastructure Act mandates open source. AI models open-sourced after 2-year proprietary window for vendor-neutral re-implementation.

Public verifier nodes

Civil society can verify independently

Public verifier nodes operable by civil society without state permission. Verification doesn't depend on the state's cooperation.

Sunset clause on AI use

Governance failure = AI suspension

If governance authority fails to publish quarterly reports for two consecutive quarters, AI uses are suspended until governance is restored. Built into the statute.

Ask the manifesto anything about Cybersecurity + DPI.

The TPM bot answers from the manifesto itself — cited to Volume, Chapter, and Section. Works in Kannada and English.

Open the chat
Next sector: Inclusive Governance · Ch 16 → All 12 sectors Open Ledger