Security & Compliance Overview
1. Our approach
DarkMatter builds custom digital solutions, develops products, supports technology, and collaborates with businesses and organizations. The current public website is a static, high-performance marketing and corporate portal hosted on Vercel and does not provide a public user-login or client portal. Our security approach is risk-based and considers the type of service, the sensitivity of data, the systems involved, and the responsibilities agreed with each customer.
We aim to protect confidentiality, integrity, availability, and appropriate use of information while keeping controls practical for the service being delivered.
2. Security program areas
Depending on the service and environment, our security program is organized around core engineering and operational pillars:
npm audit checks.
The static architecture reduces the exposed server-side attack surface, but it does not make the risk of SQL injection, remote code execution, XSS, supply-chain issues, account compromise, or other attacks zero. Client-side validation and encoding are useful safeguards but are not a substitute for server/provider validation and secure configuration.
3. Customer responsibilities
Customers are responsible for the security of their own accounts, endpoints, credentials, users, content, integrations, permissions, and configurations unless the applicable SOW assigns a responsibility to DarkMatter. Customers should use unique passwords, enable available MFA, limit access, maintain backups where appropriate, and promptly report suspected compromise.
4. Incident reporting
Report suspected vulnerabilities, unauthorized access, data exposure, or other security incidents directly to our security desk:
Security Incident Response Protocol
Email: support@officialdarkmatter.com
Include enough technical detail for triage, but do not include passwords, private keys, or unnecessary personal data.
DarkMatter’s Founder & CEO, Dev Bhunwal, and the core engineering desk supervise initial response. DarkMatter will assess reports and take reasonable steps to investigate, contain, recover, document, and respond.
Where available, deployment rollback and hosting-provider controls may be used. If an incident affects customer data processed under a contract, DarkMatter will follow the notice and cooperation obligations in that contract or DPA. Where Indian law applies, incident handling and reporting will take account of applicable CERT-In directions and other legal requirements.
5. Compliance framework
DarkMatter aims to comply with privacy, information-technology, employment, intellectual-property, and other laws that apply to the relevant service and location. Depending on the facts, this may include the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable rules in India, applicable CERT-In directions, the GDPR or UK GDPR where applicable, and other local requirements.
No False Certification Claims: This page does not mean that DarkMatter is certified under ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, or any other framework. No certification is claimed by this page. Customer-specific compliance commitments must be documented in a signed agreement after an appropriate review.
6. Client data processing
When DarkMatter acts as a service provider or processor for a customer, the customer generally determines the purposes and instructions for processing. The parties should execute a tailored Data Processing Addendum (DPA) before personal data is processed. The DPA should cover the data categories, purposes, instructions, confidentiality, subprocessors, security measures, assistance, incident response, deletion/return, and audit information.
7. Security questions and reviews
Customers with security questionnaires or diligence requests may contact support@officialdarkmatter.com. We may provide information appropriate to the engagement, subject to confidentiality, security, and resource limitations. We do not disclose sensitive architecture details publicly.
8. Current claims
DarkMatter will not publish customer names, adoption numbers, performance metrics, product capabilities, security certifications, or compliance claims unless the underlying fact is verified and authorized for publication. Product pages will identify products as In Development, Coming Soon, or Concept/Planned where applicable.