Security & Vulnerability Policy
The Rotaract Club of SVIT maintains strict standards of digital security, confidentiality, and data protection across our official web infrastructure (rcsvit.org). We recognize the importance of safeguarding student information, event attendee records, and club administration channels.
1. Security Architecture & Controls
🔒 HTTPS & HSTS
All traffic is encrypted via 256-bit TLS 1.3. Strict-Transport-Security (HSTS) is permanently enforced with 1-year preload rules.
🛡️ Content Security Policy
Rigid CSP headers whitelist only trusted Google and official CDN endpoints, mitigating Cross-Site Scripting (XSS) risks.
🔑 Least-Privilege Firestore
Database rules strictly isolate private student data. Member and scanner portals require authenticated cryptographic tokens.
⚡ Global CDN Defense
Hosted behind Google Cloud edge infrastructure with built-in Layer 3/4/7 DDoS mitigation and automated certificate renewal.
2. Student & Member Data Confidentiality
We apply the principle of data minimization:
- No Plaintext Passwords: Authentication is handled via secure Firebase Identity Services with cryptographically salted credentials.
- Role-Based Access: Only designated, club-chartered board members hold administrative access to event attendee manifests.
- Encrypted in Transit & At Rest: All stored documents are encrypted using AES-256 in Google Cloud data centers located within India.
3. Responsible Vulnerability Disclosure Program
We welcome security research from students, developers, and ethical cybersecurity specialists. If you discover a vulnerability or security flaw in our website or portals, please help us protect the community by practicing responsible disclosure.
Safe Harbor Commitment: We will not pursue legal action against researchers who report vulnerabilities in good faith, avoid privacy violations, do not destroy data, and provide us reasonable time to patch the issue before public disclosure.
Guidelines for Security Researchers:
- Send findings directly to our technical lead at rotaract_svit@saividya.ac.in.
- Include a detailed proof of concept (PoC), steps to reproduce, and impact assessment.
- Do not attempt automated volumetric denial-of-service (DDoS) or brute-force attacks against campus or hosting infrastructure.
- Do not view, modify, or exfiltrate another student's or member's personal records.
4. Response Timelines
- Initial Acknowledgment: Within 48 hours of report submission.
- Triage & Validation: Within 3-5 business days.
- Resolution & Patching: Critical flaws are patched immediately; standard updates ship within 14 days.
5. Contact Technical Support
For urgent security notices, incident reports, or data inquiries:
Technical & Digital Initiatives Team
Rotaract Club of SVIT · R.I. District 3192
Email: rotaract_svit@saividya.ac.in