Security Overview
How we protect student information, maintain system integrity, and handle vulnerability reports.
1. Defensive Measures
Railway Stadium Cricket Academy treats student and guardian information as confidential. Rather than making marketing claims of "100% security", we implement practical, verified engineering controls:
All visitor interactions are transmitted over modern TLS (HTTPS) with strict transport security and modern cipher suites.
Frontend checks exist solely for user experience. Every field is independently validated and sanitized on our secure Cloudflare Worker backend.
Cloudflare Turnstile, multi-layered rate limiting, and request volume caps protect server availability without tracking users.
Our Admissions CRM requires cryptographic authentication, strict SameSite cookies, session inactivity timeouts, and CSRF defense.
Security by Minimization: No Identity Documents Online
The safest way to protect sensitive documents (such as Aadhaar cards, passport photographs, or banking details) is not to collect them online in the first place. All physical registration paperwork is verified offline in person at Railway Stadium.
2. Responsible Disclosure Policy
If you are a security researcher and believe you have discovered a security vulnerability affecting our web infrastructure, we encourage responsible disclosure:
Security Contact: rscamoradabad@gmail.com
Machine-Readable Policy: View our /.well-known/security.txt file.
Guidelines for Researchers:
- Please provide a clear description and reproduction steps for the reported issue.
- Do not access, download, or modify another person's personal information.
- Do not perform denial-of-service (DoS) attacks or degrade services for real applicants.
- Give us a reasonable timeframe to remediate before making public disclosures.