Need deeper validation? Explore consent-gated Active Pentest
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Compliance evidence mapping

DPDP Act 2023 (India) evidence mapping

BreakMesh maps each safe scan finding to the Digital Personal Data Protection Act, 2023 (DPDP Act) provision it provides evidence for — principally the Section 8(5) obligation to implement "reasonable security safeguards" against personal data breach, and the related notice, consent, and breach-notification provisions. This is a technical evidence layer for a Data Fiduciary's DPDP program, not a legal compliance certification.

92 checks mapped 8 Digital Personal Data Protection Act provisions Non-destructive scans

BreakMesh helps you gather audit evidence and reduce risk. It maps findings to control evidence to support your assessment — it does not by itself make your organization compliant or certified.

How the mapping works

Every safe check BreakMesh runs on a verified target is linked to the DPDP Act 2023 (India) Digital Personal Data Protection Act provisions it produces evidence for. When a scan completes you get a report that groups findings and passed checks by Digital Personal Data Protection Act provisions, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.

DPDP Act 2023 (India) coverage

Rule 6(a)

  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • Cookie Security
  • CSP Quality Review
  • Deprecated Browser APIs
  • Directory Listing
  • Sitemap and Robots Exposure
  • Error Disclosure
  • Error Disclosure Expansion
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure
  • HSTS Strength
  • HTTP/2 and HTTP/3 Support
  • HTTPS Redirect
  • Mixed Content Detection
  • Secrets in JavaScript Bundles
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Server Header Disclosure
  • Session Cookie Scope
  • Source Map Exposure
  • Subresource Integrity (SRI) Missing
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • Trusted Types Signal

Rule 6(b)

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • Endpoint Auth Indicators
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Session Fixation Check
  • Weak Password Policy Review

Rule 6(d)

  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
  • Mobile App Static Analysis (APK/IPA)
  • Service/Version CVE Hints (Advisory)

Sec 11-14

  • Cookie Consent Mechanism
  • GDPR/CCPA Data Subject Rights
  • Privacy and Terms Evidence

Sec 6

  • Cookie Consent Mechanism
  • GDPR/CCPA Data Subject Rights
  • Privacy and Terms Evidence

Sec 8(4)

  • Cookie Consent Mechanism
  • GDPR/CCPA Data Subject Rights
  • Privacy and Terms Evidence

Sec 8(5)

  • Account Enumeration Indicators
  • AI Response Data Leakage
  • Auth Bypass Probes
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • Business Logic — Price Manipulation
  • BOLA / IDOR Two-Account Comparison
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • Cookie Security
  • Credentialed Test-Account Checks
  • CSP Quality Review
  • CSRF Protection Enforcement
  • Dependency CVE Matching (SBOM)
  • Deprecated Browser APIs
  • Directory Listing
  • Sitemap and Robots Exposure
  • DNS Basics
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Drive-by Download / Malicious Redirect Chain
  • Endpoint Auth Indicators
  • Error Disclosure
  • Error Disclosure Expansion
  • File Upload Bypass
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure
  • Header Injection
  • HSTS Strength
  • HTTP/2 and HTTP/3 Support
  • HTTPS Redirect
  • IDOR (Two-Account)
  • Insecure Deserialization (Timing)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • API Mass Assignment
  • MFA Configuration Indicators
  • Mixed Content Detection
  • Mobile App Static Analysis (APK/IPA)
  • OAuth 2.0 / OIDC Security Checks
  • Open Redirect
  • Open Redirect (Active)
  • Origin Exposure Check
  • HTTP Parameter Pollution (HPP)
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Path Traversal
  • Harmless Reflected XSS Indicators
  • HTTP Request Smuggling / Desync Readiness
  • Open Risky Ports
  • Secrets in JavaScript Bundles
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Server Header Disclosure
  • Service/Version CVE Hints (Advisory)
  • Session Cookie Scope
  • Session Fixation Check
  • Source Map Exposure
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • Subresource Integrity (SRI) Missing
  • SSRF (Callback)
  • SSTI Template Injection Indicator
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk
  • AI System Prompt Exposure
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • Training Data Extraction Indicator
  • Trusted Types Signal
  • Weak Password Policy Review
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection

Sec 8(6)

  • Mail Security SPF/DKIM/DMARC
  • Blocklist and Reputation Checks
  • Security Contact Evidence