PedolOne is a privacy-first data vaulting and controlled sharing platform tailored for fintech organizations. This README outlines the architecture, implemented features, security measures, compliance mechanisms, and future scope.
- Backend: FastAPI (Python) + MongoDB
- Frontend: ReactJS with WebSocket support
- Authentication: JWT-based + OTP verification
- Database: MongoDB with TTL-based expiration
- PII tokenization and encryption
- Consent-based data sharing with OTP
- Inter-org data contracts
- Real-time monitoring and alerting
- Audit logging and access control
Aadhaar, PAN, Bank Account, UPI, GST, IT Form 16, Passport, Driving License, IFSC, Credit/Debit Cards
- AES-256 (Fernet), HMAC-SHA256, Format-Preserving Encryption
- BIN-preserving (future scope)
- OTP-based consent
- Purpose-level granularity
- Consent audit trails
- Consent revocation (future scope)
- Email OTP, SMS OTP (planned), JWTs
- Role-based access & session cleanup
- IP geolocation & alerting
- Failed login, data request thresholds
- Suspicious activity detection (future AI)
- HMAC for data & file integrity
- CSV signature checks
Tracks user ID, actions, IP, location, timestamps, and data type
IP-based tracking with anonymization and user consent
Logs contract IDs, action types, IP, geo-info, and timestamps
Includes tokenized ID, resource type, purposes, retention, timestamps, signatures
Live dashboards for:
- Consent
- Purpose specificity
- Retention compliance
- Security policy adoption
- Bilateral contracts with defined PII, purpose, and duration
- Audit-ready provisions
- Individual or bulk
- OTP-based user consent
- Policy generation and audit logging
- Access, portability, lawful processing, minimization, encryption
- Aadhaar Act: Consent, purpose limitation, logging
- RBI Guidelines: Localization, encryption, audit trails
Mitigates: breaches, consent violations, retention risks
Includes: detection, assessment, remediation, user & regulator notification
- Secure HTTP headers (X-Content, X-Frame, XSS Protection, etc.)
- CORS restrictions & token-safe sessions
- PII validation, input sanitization
- Token expiration & secure logout
- TLS, access controls, encrypted backups
- Audit logging for DB access
- Add rate-limiting, fine-grained roles
- Expand consent features
- Draft privacy & incident response policies
- Zero-trust security
- Automated compliance checks
- Enhanced UX for privacy & transparency
PedolOne is a robust, privacy-focused system implementing secure data vaulting, policy-based sharing, audit readiness, and strong compliance with GDPR and Indian regulations. Continuous improvements and risk assessments will ensure future regulatory adaptability.
| Category | Status |
|---|---|
| Data Protection | Tokenization + Encryption |
| Consent | OTP + Per-type Consent |
| Audit Logging | Full Action Logging |
| Monitoring | Real-time Alerts |
| Policy Mgmt | Auto Expiry + Signature |
| Inter-org Sharing | Contract-based |
| Geolocation | IP-based Location Checks |
| Incident Response | Automated Detection |
- Backend: FastAPI, MongoDB
- Frontend: ReactJS, WebSocket
- Security: JWT, OTP, HMAC, AES
- Monitoring: ip-api.com, custom alerts
For further information, reach out to:
Team NFSU – Bhaskar Bhar, Aryan Sakaria, Deeksha Singh