The delivery layer of digital rights.
Five operating institutions tied to the Karnataka State Service Log (KSSL) — the cryptographic floor — plus Digital Public Infrastructure, the open public datasets, and the citizen technology layer that runs on top of the spine. Rights live in Vol I Ch 6; this chapter owns delivery.
The structural failures in Cybersecurity, DPI & Citizen Tech.
Digital governance expands the attack surface. Without serious cybersecurity, the operating spine becomes a single point of failure for fraud, identity theft, ransomware, and politically motivated leaks.
Inconsistent security posture
Karnataka's departments vary widely. Many run on outdated stacks with inconsistent patching and incident response.
Vendor + contractor weak links
Outsourcing the system does not outsource accountability for the breach. The vendor's bug becomes the citizen's data leak.
Resident-side awareness uneven
Digital exclusion compounds the security gap. A resident assisted by an unknown kiosk operator presents a different attack surface.
DPI under-utilised by departments
India Stack exists nationally; Karnataka hasn't built the operational layer that uses it consistently across departments.
Single-system silos
Identity, payments, signing, storage reinvented per department. Resident stuck navigating seams; integrity not detectable.
Security is not an IT add-on. It is a governance guarantee. Karnataka treats the cryptographic floor as durable infrastructure — like roads, not like software-as-a-service.
Five operating institutions. One cryptographic floor.
KSSL is the single logging + anchoring layer. CSOC has compel-patching authority. Hardware Security Modules + threshold cryptography make bulk operations require multiple signoffs. Post-quantum cryptography by default.
Three operating loops.
Three flows that define what the cryptographic floor means operationally — for a citizen, a developer, and an auditor.
See who accessed your data, live.
Every state system access to your data generates a KSSL entry.
Your JANATA Citizen role-card shows the access log live — accessing officer ID, records accessed, reason code.
Suspicious access? Raise a Grievance Justice Authority ticket from JANATA.
Break-glass override? You're notified within 24 hours; quarterly review panel audits the override.
Karnataka's code is yours to audit.
State systems built under the open-source mandate (Karnataka State Digital Infrastructure Act).
Source code published; AI models open-sourced after a 2-year proprietary window.
Public verifier nodes can verify KSSL anchors without state permission.
Bug bounty triage time ≤24 hours median; reproducible builds for KSSL itself.
Detect tampering mathematically.
Civil-society Independent Audit Board has standing to audit every state digital system.
Threshold cryptography means no single admin can do bulk damage; multiple keys required.
AI-Use Register lists every state AI with description, training data, performance, annual bias audit.
Independent witness co-signing of KSSL anchors — trust isn't concentrated in the executive.
KSSL live in Year 1. Universal PQC adoption by Year 5.
The cryptographic floor is built once and runs forever. The hard work is structural — getting the floor right.
- Karnataka State Service Log open-source reference implementation published
- Karnataka Cyber Security + Citizen Consent Act tabled
- CSOC interim leadership named; bug-bounty programme launch
- Software Bill of Materials mandate published
- KSSL live across pilot high-stakes systems
- PQC adoption on new builds 100% (procurement standard binding)
- CSOC fully operational with compel-patching authority
- Citizen Consent Ledger live in 3 sectors (Health, Education, Welfare)
- KSSL anchoring across every state digital service
- CSOC mean-time-to-patch on compelled orders ≤72 hours
- Citizen Consent Ledger revocation propagation ≤1 hour
- Karnataka Open Data Portal coverage ≥5,000 datasets
- Streaming KSSL anchors with defined window
- Bug-bounty triage time ≤24 hours median
- Karnataka Open Data Portal coverage ≥10,000 datasets
- Legacy systems on PQC migration plan with 15-year outer bound
- Karnataka's cryptographic floor exported as the open-source reference implementation for other Indian states
- Independent witness network distributed across civil society
- Anti-capture architecture culturally embedded in cadre training
- PQC migration complete across inherited systems
Six numbers we publish every quarter.
Full set in Vol III App A. Each KPI has a published baseline, Year-1 target, Year-5 target — and where relevant, a Year-10 commitment.
Why Cybersecurity, DPI & Citizen Tech can't quietly be reversed.
The cryptographic floor exists precisely to prevent quiet reversal. Six structural mechanisms enforce that.
Trust is in the math, not the admin
Every entry hashed + batched + anchored into a publicly verifiable append-only structure. Altering an entry after the fact is mathematically detectable.
No single admin can do mass damage
Hardware Security Modules + threshold cryptography mandatory for any bulk operation. No single administrator's keys are sufficient.
Audit access not at executive discretion
CSOC has audit access independent of the executive. Cannot be quietly defunded or restructured; statutory.
State software published under public licence
Karnataka State Digital Infrastructure Act mandates open source. AI models open-sourced after 2-year proprietary window for vendor-neutral re-implementation.
Civil society can verify independently
Public verifier nodes operable by civil society without state permission. Verification doesn't depend on the state's cooperation.
Governance failure = AI suspension
If governance authority fails to publish quarterly reports for two consecutive quarters, AI uses are suspended until governance is restored. Built into the statute.
The spine runs through every sector.
Cyber + DPI isn't a sector — it's the floor every other sector stands on.
Ask the manifesto anything about Cybersecurity + DPI.
The TPM bot answers from the manifesto itself — cited to Volume, Chapter, and Section. Works in Kannada and English.