Security
Security is treated as an operational layer of MDM PASS, not a marketing claim.
1. Current controls
The current platform architecture uses protected administrative routes, role-based access, CSRF controls, rate limiting, protected storage and encrypted local records in the PHP backend. Public forms are designed to minimise unnecessary sensitive data.
2. No absolute guarantee
No internet service can be described as perfectly secure. MDM reviews security controls progressively and may change, restrict or disable features when necessary to protect data or system integrity.
3. Responsible reporting
If you identify a suspected vulnerability, unintended data exposure or security issue, use the unified Ideas & Requests page and select “Security concern”. Provide enough detail for investigation without exploiting the issue or accessing data that is not yours.
4. Confidential material
Confidential partnership dossiers and administrative material are not intended to be exposed through public direct-download links. Access can require review, authorisation or separate delivery.
5. User responsibility
Users should use current browsers, protect their devices and email accounts, avoid sharing authentication details, and never send passwords or payment-card credentials through general MDM forms.

