MENU

NT NT
Live
Security Policy

Security Policy

How we protect your data, accounts, and transactions with industry-grade security practices.

Home Legal & Support Security Policy
Last Updated: April 25, 2026

Security at a Glance

SSL / HTTPS
All traffic encrypted via SSL/TLS on Hostinger
bcrypt Hashing
Passwords hashed with PHP password_hash() — never plain-text
PDO Prepared Statements
All DB queries parameterized — zero SQL injection risk
RBAC
Role-based access control on every admin panel page
PCI-DSS (Razorpay)
Card data handled by Razorpay — we never see card numbers
Activity Logs
All logins logged with IP, geo-location, device info

Transport Security (HTTPS / SSL)

All communication between your browser and vpn.mitkar.com is encrypted using SSL/TLS provided by Hostinger's managed SSL certificate. This means:

Always verify that the URL shows https://vpn.mitkar.com with a padlock icon before entering any credentials or payment information.

Authentication Security

Password Hashing

All admin account passwords are stored using PHP's password_hash() function with the PASSWORD_BCRYPT algorithm. Key properties:

Session Management

Role-Based Access Control (RBAC)

Every single page in the admin panel verifies the user's role and session before rendering any content or allowing any action:

Database Security

Payment Security

We never handle, store, or process raw card numbers, CVV codes, or banking credentials. All payment card processing is delegated entirely to PCI-DSS Level 1 certified payment gateways.

Activity Logging & Monitoring

Our platform maintains comprehensive activity logs for security monitoring:

Activity logs enable the Main Admin to detect unauthorized access attempts, suspicious financial activity, and platform misuse.

Vulnerability Reporting

If you discover a security vulnerability in our platform, we encourage responsible disclosure. Please:

We appreciate responsible security researchers who help us maintain a secure platform for all users.

Your Security Responsibilities

Platform security is a shared responsibility. As an admin account holder, you are responsible for:

Admin
Neon Tunnel Support
Checking status...