Privacy Policy
Effective Date: August 2025 · Last Revised: 2026
1. Executive Overview
dikshantlather.blog is operated by Dikshant Lather as both a personal engineering portfolio and an open technical community for cybersecurity practitioners. We hold data minimization, privacy by design, and strict security hygiene as non-negotiable principles. We do not sell your personal information, nor do we deploy commercial behavioral tracking or third-party advertising trackers.
2. Data We Collect
- Account Credentials: If you register as an author or commenter, we collect your display name, unique username, and email address. Passwords are cryptographically hashed using standard
Argon2idorBcrypthashing; plaintext passwords never touch disk or memory unhashed. - Security Telemetry & Audit Logs: To safeguard the community from brute-force attacks and abuse, we log client IP addresses, User-Agent strings, and authentication events in an encrypted audit ledger.
- User-Generated Content: Articles, comments, likes, and bookmarks you author are stored in our relational database and associated with your profile. Markdown content is parsed through an Abstract Syntax Tree (AST) and sanitized via HTMLPurifier.
- Inquiry Submissions: Information provided via our consulting inquiry form (name, email, project parameters) is used solely to respond to your professional request.
3. GDPR & Global Rights (Data Portability & Erasure)
Regardless of whether you reside in the European Union, Australia, Canada, or the United States, you retain full sovereignty over your data:
- Data Portability: Authenticated users can request an automated machine-readable JSON export of all personal profile data, authored articles, and comments directly from their account profile settings.
- Right to Erasure (Be Forgotten): You may request account deletion at any time. Upon deletion, your identifying profile data is purged, and public comments are permanently dissociated or sanitized.
4. Security Safeguards
Our infrastructure enforces defense-in-depth: mandatory HTTPS (TLS 1.3), Content Security Policy (CSP) headers, HTTP-only SameSite secure session cookies, strict CORS, and real-time rate limiting to defend against automated denial-of-service and credential stuffing.
5. Contact Data Controller
For inquiries, data protection requests, or vulnerability disclosures, reach out directly to the site operator at: privacy@dikshantlather.blog.