How the mapping works
Every safe check BreakMesh runs on a verified target is linked to the DPDP Act 2023 (India) Digital Personal Data Protection Act provisions it produces evidence for. When a scan completes you get a report that groups findings and passed checks by Digital Personal Data Protection Act provisions, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.
DPDP Act 2023 (India) coverage
Rule 6(a)
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Open Security Group Ingress
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Open NSG Ingress Rules
- Azure Public Blob Storage Exposure
- Cookie Security
- CSP Quality Review
- Deprecated Browser APIs
- Directory Listing
- Sitemap and Robots Exposure
- Error Disclosure
- Error Disclosure Expansion
- GCP Open VPC Firewall Ingress
- GCP Public Cloud Storage Exposure
- HSTS Strength
- HTTP/2 and HTTP/3 Support
- HTTPS Redirect
- Mixed Content Detection
- Secrets in JavaScript Bundles
- Security Headers
- Sensitive Files
- Sensitive Response Pattern Detection
- Server Header Disclosure
- Session Cookie Scope
- Source Map Exposure
- Subresource Integrity (SRI) Missing
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
- Trusted Types Signal
Rule 6(b)
- Account Enumeration Indicators
- Auth Bypass Probes
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- BOLA / IDOR Two-Account Comparison
- Credentialed Test-Account Checks
- CSRF Protection Enforcement
- Endpoint Auth Indicators
- IDOR (Two-Account)
- Login Rate-Limit Simulation
- Login Surface Controls
- API Mass Assignment
- MFA Configuration Indicators
- OAuth 2.0 / OIDC Security Checks
- Password Reset Flow Checks
- Password Spray Indicator
- Session Fixation Check
- Weak Password Policy Review
Rule 6(d)
- Dependency CVE Matching (SBOM)
- Drive-by Download / Malicious Redirect Chain
- Mobile App Static Analysis (APK/IPA)
- Service/Version CVE Hints (Advisory)
Sec 11-14
- Cookie Consent Mechanism
- GDPR/CCPA Data Subject Rights
- Privacy and Terms Evidence
Sec 6
- Cookie Consent Mechanism
- GDPR/CCPA Data Subject Rights
- Privacy and Terms Evidence
Sec 8(4)
- Cookie Consent Mechanism
- GDPR/CCPA Data Subject Rights
- Privacy and Terms Evidence
Sec 8(5)
- Account Enumeration Indicators
- AI Response Data Leakage
- Auth Bypass Probes
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Open Security Group Ingress
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Open NSG Ingress Rules
- Azure Public Blob Storage Exposure
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- Business Logic — Price Manipulation
- BOLA / IDOR Two-Account Comparison
- Web Cache Poisoning Readiness
- Command Injection (Timing)
- Cookie Security
- Credentialed Test-Account Checks
- CSP Quality Review
- CSRF Protection Enforcement
- Dependency CVE Matching (SBOM)
- Deprecated Browser APIs
- Directory Listing
- Sitemap and Robots Exposure
- DNS Basics
- DNSSEC Review
- WHOIS and Domain Expiry
- Drive-by Download / Malicious Redirect Chain
- Endpoint Auth Indicators
- Error Disclosure
- Error Disclosure Expansion
- File Upload Bypass
- GCP Open VPC Firewall Ingress
- GCP Public Cloud Storage Exposure
- Header Injection
- HSTS Strength
- HTTP/2 and HTTP/3 Support
- HTTPS Redirect
- IDOR (Two-Account)
- Insecure Deserialization (Timing)
- Login Rate-Limit Simulation
- Login Surface Controls
- Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
- API Mass Assignment
- MFA Configuration Indicators
- Mixed Content Detection
- Mobile App Static Analysis (APK/IPA)
- OAuth 2.0 / OIDC Security Checks
- Open Redirect
- Open Redirect (Active)
- Origin Exposure Check
- HTTP Parameter Pollution (HPP)
- Password Reset Flow Checks
- Password Spray Indicator
- Path Traversal
- Harmless Reflected XSS Indicators
- HTTP Request Smuggling / Desync Readiness
- Open Risky Ports
- Secrets in JavaScript Bundles
- Security Headers
- Sensitive Files
- Sensitive Response Pattern Detection
- Server Header Disclosure
- Service/Version CVE Hints (Advisory)
- Session Cookie Scope
- Session Fixation Check
- Source Map Exposure
- Safe SQL Injection Indicators
- SQL Injection (Boolean-Blind)
- SQL Injection (Error-Based)
- Subresource Integrity (SRI) Missing
- SSRF (Callback)
- SSTI Template Injection Indicator
- Subdomain Discovery (Certificate Transparency)
- Subdomain Takeover Risk
- AI System Prompt Exposure
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
- Training Data Extraction Indicator
- Trusted Types Signal
- Weak Password Policy Review
- XSS — Reflected
- XSS — Stored
- XXE Injection
Sec 8(6)
- Mail Security SPF/DKIM/DMARC
- Blocklist and Reputation Checks
- Security Contact Evidence