Skip to main content
Defense & Integrity

Security Overview

How we protect student information, maintain system integrity, and handle vulnerability reports.

1. Defensive Measures

Railway Stadium Cricket Academy treats student and guardian information as confidential. Rather than making marketing claims of "100% security", we implement practical, verified engineering controls:

Encryption in Transit

All visitor interactions are transmitted over modern TLS (HTTPS) with strict transport security and modern cipher suites.

Independent Server Validation

Frontend checks exist solely for user experience. Every field is independently validated and sanitized on our secure Cloudflare Worker backend.

Anti-Bot & Abuse Prevention

Cloudflare Turnstile, multi-layered rate limiting, and request volume caps protect server availability without tracking users.

Protected Administrative Access

Our Admissions CRM requires cryptographic authentication, strict SameSite cookies, session inactivity timeouts, and CSRF defense.

Security by Minimization: No Identity Documents Online

The safest way to protect sensitive documents (such as Aadhaar cards, passport photographs, or banking details) is not to collect them online in the first place. All physical registration paperwork is verified offline in person at Railway Stadium.

2. Responsible Disclosure Policy

If you are a security researcher and believe you have discovered a security vulnerability affecting our web infrastructure, we encourage responsible disclosure:

Security Contact: rscamoradabad@gmail.com

Machine-Readable Policy: View our /.well-known/security.txt file.

Guidelines for Researchers:

  • Please provide a clear description and reproduction steps for the reported issue.
  • Do not access, download, or modify another person's personal information.
  • Do not perform denial-of-service (DoS) attacks or degrade services for real applicants.
  • Give us a reasonable timeframe to remediate before making public disclosures.