# Data Encryption Verification Log (DPDP Compliance)

| Verification Item | Status | Details | Date Verified |
| :--- | :--- | :--- | :--- |
| Database Encrypted at Rest? | No / Not Supported | Access controlled via authentication and permissions. | 2026-04-05 |
| File Storage Encrypted at Rest? | No / Not Supported | Standard shared hosting; relies on perimeter security. | 2026-04-05 |
| Encryption Standard | N/A | AES-256 not applied to stored data by default. | 2026-04-05 |

## Provider Confirmation Notes
Received from Hostripples Support:
Database Encryption (MySQL): The MySQL databases on our shared hosting servers are not encrypted at rest by default at the individual database level. However, access to databases is strictly controlled via authentication, permissions, and secure network configurations.

File Storage Encryption: The server disks used in our standard shared hosting environment are not configured with full disk encryption (FDE). Data is stored on secured storage systems with strict access controls and monitoring in place.

Encryption Standards: Since encryption at rest is not enabled by default on this hosting plan, AES-256 (or similar disk-level encryption standards) is not currently applied to stored data.

Recommendation: Upgrading to a dedicated server or VPS environment would allow for full disk encryption (LUKS or similar) and database-level encryption.

## Compliance Gap & Risk Assessment
- **Status:** **RISK ACKNOWLEDGED AND ACCEPTED BY ADMIN**
- **Regulatory Framework:** DPDP Act 2023 (Section 8 - Obligation to safeguard personal data).
- **Current Vulnerability:** Shared hosting disks do not support AES-256 hardware or volume-level encryption at rest. If the underlying physical storage of the host is compromised, sensitive health data may be exposed.
- **Remediation Action Required:** Review hosting options periodically. For now, the Administrator has reviewed and accepted the operational risk of standard shared hosting access controls, with no immediate plans for VPS migration.
- **Migration Target Date:** N/A / Risk Accepted.