KKissan Ki Pehchan
Assurance

Security, Privacy and Consent

Security and privacy controls for live camera/microphone processing, selected evidence, research and government data.

BlueprintVersion 0.25 Aug 2026

Data classification

Classify identity, consent, precise geospatial data, live room metadata, transcript, selected frames, any raw recording, crop/treatment history, research traces, model logs, officer records and audit data separately.

  • Explain camera and microphone use before joining.
  • Display whether the AI can currently see/hear and whether any recording is active.
  • Separate consent for service delivery, officer review, full-call recording and evaluation use.
  • Allow camera-off, mute and end-call at all times.
  • Notify the farmer before an officer joins.

Media security

  • Use DTLS-SRTP/WebRTC transport and short-lived participant tokens.
  • Restrict room discovery and participant roles.
  • Rate-limit tracks, frames, uploads and joins.
  • Validate/decode media in isolated workers with size/time limits.
  • Store selected frames encrypted with case/purpose metadata.
  • Disable egress/recording by default and audit every enablement.

Minimization

Prefer pseudonymous case IDs, selected frames rather than unrestricted video, sanitized transcript, coarse location where sufficient, and temporary processing. A provider receives continuous media only when explicitly required by an approved media service role—not as general reasoning input.

Retention

Define separate approved periods for room metadata, raw audio, transcript, selected frames, explicit stills, optional full-call recording, diagnosis, model traces, tool results, officer review and anonymized analytics. Full-call retention must never be inherited from selected-frame retention.

Access and audit

Use least privilege, attribute-based location/case restrictions, break-glass workflow, watermarking/export controls and immutable audit of room joins, recording changes, frame access and deletion.