Platform-side protections
- HTTPS encryption for every request
- Role-based access control for DDOs, officers and admins
- Aadhaar authentication routed via UIDAI's secure APIs
- Encrypted storage of Aadhaar and bank details
- Audit logging of every sensitive action
- Periodic security audits per CERT-In guidelines
Your responsibilities
- Never share your password or OTP with anyone
- Log out on shared or public devices
- Keep your Aadhaar-linked mobile active
- Change your password every 90 days
- Report suspicious login alerts immediately
Fraud warning
No genuine government officer will ask for your OTP over phone, SMS or WhatsApp. Any such request is a phishing attempt.
Need official help?
For anything related to actual salary, service book or pension records, always use the official Bihar HRMS portal or contact your DDO.
