Security Policy
We are committed to protecting our website, donor information, volunteer data, and digital infrastructure. If you discover a security vulnerability, we encourage responsible disclosure.
1. Our Commitment
At IYIMHHSE, we value privacy, data security, responsible disclosure, continuous security improvements, and ethical research.
Protecting our beneficiaries, donors, volunteers, and partners is a core priority. We work actively to maintain clean and secure digital operations.
2. Reporting a Vulnerability
Preferred Report Contents:
- Vulnerability description
- Steps to reproduce
- Affected page/endpoint
- Screenshots (if any)
- Proof of Concept (PoC)
- Remediation suggestions
3. Responsible Disclosure
Responsible disclosure helps improve the platform for everyone. We request that security researchers:
- Act in good faith: Conduct testing without intent to harm or exploit.
- Avoid accessing user data: Stop immediately if private details or logs are exposed.
- Avoid disrupting services: Do not degrade or crash site operations.
- Avoid social engineering: Do not target staff or volunteers with phishing.
- Avoid Denial-of-Service: Do not launch resource-exhausting DoS or DDoS.
- Provide reasonable time: Give us time to patch issues before public write-ups.
4. Scope
Out of Scope: Third-party integrations and platforms (such as GitHub repositories, Cloudflare CDNs, Zoho Mail, Firebase APIs, Google Services, etc.) should be reported directly to their respective providers.
Only report these to IYIMHHSE if the vulnerability is caused directly by an active misconfiguration of our specific assets.
5. Active Security Measures
Cloudflare Protection
Edge proxy configuration shielding routing targets, caching static resources, and mitigating DDoS attacks.
DNSSEC
Domain Name System Security Extensions cryptographically signing records to prevent DNS spoofing.
HTTPS Everywhere
Enforcing TLS encryption on all connections to protect user data from packet sniffing.
HSTS
HTTP Strict Transport Security headers ensuring browsers interact with the site exclusively over secure channels.
Email Authentication
Enforced SPF, DKIM, and DMARC policies to prevent domains from being spoofed for email phishing.
Bot Protection
Heuristics-based traffic management guarding registration forms from spam and scraping loops.
Secure Hosting
Assets hosted on premium cloud providers with strict environment segmentation and compliance controls.
Routine Updates
Regular review and updating of third-party libraries, packages, scripts, and build chains.
Least Privilege Access
Enforcement of strict database rules. Anonymous access is limited strictly to write-only functions for logs.
Responsible Monitoring
Regular oversight of active database limits, configurations, and edge caching rules.
6. Safe Harbor
IYIMHHSE appreciates responsible security research performed in good faith. Researchers who follow this policy will not face legal action from IYIMHHSE for testing that avoids unauthorized data access, service disruption, or privacy violations.
Please note: As a volunteer-run youth initiative, we do not promise bug bounties or offer financial compensation for reporting security issues.
7. Privacy Reminder
Keep Reports Clean
To maintain compliance with privacy regulations, reports must never contain sensitive credentials or details.
Do NOT include the following in reports:
- Passwords / API Tokens
- Personal Identifiable Data
- Payment credentials
- Sensitive donor names
- Volunteer personal files
Only provide the minimum technical proof required to reproduce the issue.