Security Policy

We are committed to protecting our website, donor information, volunteer data, and digital infrastructure. If you discover a security vulnerability, we encourage responsible disclosure.

1. Our Commitment

At IYIMHHSE, we value privacy, data security, responsible disclosure, continuous security improvements, and ethical research.

Protecting our beneficiaries, donors, volunteers, and partners is a core priority. We work actively to maintain clean and secure digital operations.

Privacy First No third-party tracking pixel cookies or commercial data brokers.
Data Security Write-only frontend policies to protect transaction confirmation logs.
Responsible Disclosure Appreciation and protection for reports made in ethical good faith.
Continuous Audits Regular review of access control lists and CDN configuration rules.

2. Reporting a Vulnerability

Email Address contact@iyimhhse.org.in
Expected Response Time Within 72 hours
Severity Assessment Based on real impact and exploitability

Preferred Report Contents:

  • Vulnerability description
  • Steps to reproduce
  • Affected page/endpoint
  • Screenshots (if any)
  • Proof of Concept (PoC)
  • Remediation suggestions

3. Responsible Disclosure

Responsible disclosure helps improve the platform for everyone. We request that security researchers:

  • Act in good faith: Conduct testing without intent to harm or exploit.
  • Avoid accessing user data: Stop immediately if private details or logs are exposed.
  • Avoid disrupting services: Do not degrade or crash site operations.
  • Avoid social engineering: Do not target staff or volunteers with phishing.
  • Avoid Denial-of-Service: Do not launch resource-exhausting DoS or DDoS.
  • Provide reasonable time: Give us time to patch issues before public write-ups.

4. Scope

Out of Scope: Third-party integrations and platforms (such as GitHub repositories, Cloudflare CDNs, Zoho Mail, Firebase APIs, Google Services, etc.) should be reported directly to their respective providers.

Only report these to IYIMHHSE if the vulnerability is caused directly by an active misconfiguration of our specific assets.

5. Active Security Measures

Cloudflare Protection

Edge proxy configuration shielding routing targets, caching static resources, and mitigating DDoS attacks.

DNSSEC

Domain Name System Security Extensions cryptographically signing records to prevent DNS spoofing.

HTTPS Everywhere

Enforcing TLS encryption on all connections to protect user data from packet sniffing.

HSTS

HTTP Strict Transport Security headers ensuring browsers interact with the site exclusively over secure channels.

Email Authentication

Enforced SPF, DKIM, and DMARC policies to prevent domains from being spoofed for email phishing.

Bot Protection

Heuristics-based traffic management guarding registration forms from spam and scraping loops.

Secure Hosting

Assets hosted on premium cloud providers with strict environment segmentation and compliance controls.

Routine Updates

Regular review and updating of third-party libraries, packages, scripts, and build chains.

Least Privilege Access

Enforcement of strict database rules. Anonymous access is limited strictly to write-only functions for logs.

Responsible Monitoring

Regular oversight of active database limits, configurations, and edge caching rules.

8. Contact Details

Get in Touch

If you have discovered a vulnerability or have general security inquiries, please use our dedicated security channel. For other organizational queries, use our main portal.