MUFAD

Security

Your account and your leads, protected

You trust MUFAD with the people who contact you. Here is how we keep that information safe.

Encrypted connections

mufad.in is served only over HTTPS, so everything between your browser or the app and our servers is encrypted.

Hashed passwords

Passwords are never stored as text. They are hashed with bcrypt, so not even we can read them.

Secure sessions

Sign-in uses a secure, HTTP-only cookie that page scripts cannot read, and requests from other websites are rejected.

Private lead data

Leads and notes are visible only to the account that owns the form. They never appear on public pages and are never indexed by search engines.

Abuse protection

Login, sign-up and password reset are rate limited to stop guessing attacks. Password reset codes expire after 10 minutes and work only once.

Same protection in the app

The Android app uses the same secure API and keeps your sign-in token in the app's private storage.

Found a security issue? Please tell us through the Contact page.