Secure PII in Desktop Application
Budget: $10 – $5,000 USD
I have a desktop-based application that processes and stores a substantial amount of personally identifiable information, and I need a focused engagement around data protection. The core objective is to harden every point at which PII is collected, transmitted, stored, and deleted, ensuring the solution withstands internal misuse as well as external threats.
Scope of work
• Perform a threat model specifically centred on how the application ingests, manipulates, and persists user data.
• Recommend and help implement strong cryptographic controls for data at rest and in transit—ideally AES-256 for storage and TLS 1.3 for communication, or a comparably robust approach you can justify.
• Review existing authentication and access-control logic, introducing least-privilege and role-based enforcement where gaps appear.
• Provide secure-coding guidance for the current desktop tech stack (the codebase is in C# with .NET 7; if deeper static analysis is required, feel free to suggest tools such as SonarQube or Microsoft’s SDL tools).
• Deliver concise, actionable documentation: updated data-flow diagrams, new security controls, configuration steps, and guidance my team can maintain after your engagement.
Acceptance criteria
1. A documented threat model that clearly lists identified risks and proposed mitigations.
2. Proof-of-concept or merged code demonstrating encryption and access-control improvements, passing unit tests.
3. Post-engagement security checklist my developers can run before each new release.
4. Final walk-through meeting where you explain the changes and hand over all artefacts.
If you have deep data-protection experience, especially around PII compliance requirements (GDPR, CCPA, etc.), you will be able to hit the ground running and keep the process smooth for my dev team.
Scope of work
• Perform a threat model specifically centred on how the application ingests, manipulates, and persists user data.
• Recommend and help implement strong cryptographic controls for data at rest and in transit—ideally AES-256 for storage and TLS 1.3 for communication, or a comparably robust approach you can justify.
• Review existing authentication and access-control logic, introducing least-privilege and role-based enforcement where gaps appear.
• Provide secure-coding guidance for the current desktop tech stack (the codebase is in C# with .NET 7; if deeper static analysis is required, feel free to suggest tools such as SonarQube or Microsoft’s SDL tools).
• Deliver concise, actionable documentation: updated data-flow diagrams, new security controls, configuration steps, and guidance my team can maintain after your engagement.
Acceptance criteria
1. A documented threat model that clearly lists identified risks and proposed mitigations.
2. Proof-of-concept or merged code demonstrating encryption and access-control improvements, passing unit tests.
3. Post-engagement security checklist my developers can run before each new release.
4. Final walk-through meeting where you explain the changes and hand over all artefacts.
If you have deep data-protection experience, especially around PII compliance requirements (GDPR, CCPA, etc.), you will be able to hit the ground running and keep the process smooth for my dev team.
Related categories:
.NET
Computer Security
C# Programming
Cryptography
C++ Programming
Encryption
Security
Data Protection