Anonymized sample · built from a real external scan · client identity redacted (shown as "Northwind Health")
Eleven11 · Dhara
DPDP-Readiness · External Surface Read · 2026

What an attacker sees — and what your DPDP obligations say about it

An outside-in read of Northwind Health's public attack surface, with each technical observation mapped to the obligation it bears on under India's Digital Personal Data Protection Act. No intrusive testing — only what is already visible to the open internet.

SUBJECT Northwind Health (health-tech SaaS) SCOPE external, outside-in DPDP ENFORCEMENT May 2027
For the developer

What to fix. Every row names a specific host and a concrete remediation — a change the engineering team can action this sprint.

For counsel / the auditor

What it bears on. Each observation is mapped to the DPDP obligation it is evidence for — so the compliance gap is legible, not buried in a scanner dump.

The one thing to act on

A secondary host, sftp.northwindhealth.in, runs a 2013-era stack (Apache 2.4.6 · OpenSSL 1.0.2k) carrying dozens of known vulnerabilities — while a support-ticketing system, a developer project server, and pre-production environments sit openly reachable on the same domain. This is the strongest available argument that "reasonable security safeguards" (DPDP §8(5)) are not yet demonstrable across the estate.

16
Subdomains exposed in public DNS/CT
23
Critical CVEs (version-matched)
46
High CVEs
40
Medium CVEs
3
Direct compliance flags
01 · The read in one paragraph

A wide surface, an old edge, and internal systems in the open

Northwind's public footprint spans 16 subdomains — and several are not customer-facing: a support-ticketing system (OTRS), a developer project server (Tuleap), operations and staging/pre-production hosts, all reachable from the open internet. The main application runs a current web server but ships a 2014-era JavaScript library (jQuery 1.11.2); a file-transfer host runs software that reached end-of-life around 2013. A wildcard TLS certificate spans hosts that appear to include a cardholder-data environment. None of this required a login or an intrusive probe to see — which is precisely why it also describes what an attacker, or a regulator asking "what safeguards can you demonstrate," would see first.

02 · The bridge — findings mapped to DPDP

Each observation, and the obligation it bears on

Technical observation DPDP obligation it bears on Owner Severity
sftp.northwindhealth.in — Apache 2.4.6 + OpenSSL 1.0.2k (EOL ~2013), 23 critical / 46 high version-matched CVEs across the estate §8(4)–(5) — appropriate technical measures & reasonable security safeguards. Unpatched, end-of-life software is the canonical example of a safeguard not being maintained. DEV — upgrade / decommission CRITICAL
otrs · tuleap · operations · techhelp — internal support, dev-project and ops systems reachable in public DNS/CT §8(4) — technical & organisational measures / access control. Support and ops tooling commonly processes personal data; public reachability is an access-control question for counsel. DEV + POLICY HIGH
*.northwindhealth.in wildcard cert — a single wildcard certificate spans hosts that appear to include a cardholder-data environment §8(5) — key-scope / safeguard boundary. A shared key across a payment-adjacent boundary widens blast radius; relevant to both DPDP safeguards and PCI scope. DEV — split cert scope MEDIUM
health.northwindhealth.in — historical URLs (public archives) reference configuration / version paths §8(4) — information disclosure minimisation. Leaked config/version detail lowers attacker cost; evidence the surface is not minimised. DEV — scrub / rotate HIGH
staging · stagingup — pre-production environments visible in public DNS/CT §8(4) — environment separation. Staging often holds copies of production personal data; public exposure is a data-minimisation question. DEV + POLICY LOW

Owner is the division that fixes each item: DEV ships a technical change; POLICY is a determination for counsel (is this personal data, is the exposure lawful, what does the client's DPDP notice say). Several are both — which is exactly why a technical audit alone, or a legal review alone, leaves the gap half-closed.

03 · For the engineering team

What to fix, host by host

sftp.northwindhealth.inApache 2.4.6 · OpenSSL 1.0.2k-fips — end-of-life ~2013; carries the bulk of the 23 critical CVEsupgrade or retire the host
www · healthjQuery 1.11.2 (2014) on a current Apache 2.4.58 — old client library, known XSS classbump jQuery to supported
otrs · tuleap · operationsinternal tooling reachable from the public internet — support/dev/ops systemsgate behind VPN / allowlist
staging · staginguppre-production environments publicly resolvableremove public DNS / auth-gate
*.northwindhealth.inwildcard certificate spanning payment-adjacent hostssplit cert scope by trust zone
04 · Why this needs two hands

The technical read and the legal read close the gap together

Dhara — the evidence

The technical facts, continuously

An outside-in scan produces the observable, dateable evidence — what is exposed, what version it runs, which CVEs it carries — and re-runs it on a schedule so the picture stays current as the surface drifts and new CVEs land.

Counsel — the determination

What the law makes of it

Whether an exposed system processes personal data, whether a safeguard is "reasonable," what the client's DPDP notice and contracts require — these are legal determinations. The evidence is only actionable once counsel characterises it.

A scanner hands a client 109 findings and no priorities. A lawyer without the technical read is arguing compliance in the abstract. Together, this document becomes a DPDP-readiness plan — a fix list for the engineers and an obligation map for the record.

Your control — by design, not by promise
On scope and standing. Dhara provides a technical read of a publicly-observable attack surface. It is not legal advice and does not itself determine DPDP compliance — the legal characterisation of any observation (whether data is "personal," whether a safeguard is "reasonable," what a Data Fiduciary's obligations are in a given matter) rests with qualified counsel. CVE counts are matched to detected software versions and indicate exposure pending validation, not confirmed exploitability. Section references are to the Digital Personal Data Protection Act, 2023.