Security
Your account and your leads, protected
You trust MUFAD with the people who contact you. Here is how we keep that information safe.
Encrypted connections
mufad.in is served only over HTTPS, so everything between your browser or the app and our servers is encrypted.
Hashed passwords
Passwords are never stored as text. They are hashed with bcrypt, so not even we can read them.
Secure sessions
Sign-in uses a secure, HTTP-only cookie that page scripts cannot read, and requests from other websites are rejected.
Private lead data
Leads and notes are visible only to the account that owns the form. They never appear on public pages and are never indexed by search engines.
Abuse protection
Login, sign-up and password reset are rate limited to stop guessing attacks. Password reset codes expire after 10 minutes and work only once.
Same protection in the app
The Android app uses the same secure API and keeps your sign-in token in the app's private storage.
Found a security issue? Please tell us through the Contact page.