1. Cybersecurity Program Overview
MUNAUGHT PRIVATE LIMITED maintains an enterprise cybersecurity program engineered to safeguard sports organizational data, domain assets, athlete records, and hosting environments.
2. Technical & Organizational Controls
Our security architecture includes:
- Encryption in Transit: Mandatory TLS 1.2/1.3 encryption across all public web and API endpoints
- Credential Protection: Cryptographic one-way hashing (bcrypt/argon2) for stored passwords
- Access Management: Principle of least privilege, role-based console access, and Multi-Factor Authentication (MFA)
- Perimeter Defense: Web Application Firewalls (WAF), rate-limiting, and automated DDoS mitigation
- Continuous Monitoring: Real-time log aggregation, intrusion detection, and automated vulnerability scanning
- Data Resilience: Encrypted offsite backups and disaster recovery failover procedures
3. Responsible Vulnerability Disclosure
We welcome reports from cybersecurity researchers. If you discover a vulnerability in MUNAUGHT systems, please submit a responsible disclosure report to [INSERT OFFICIAL SECURITY EMAIL] containing:
- Vulnerability description and potential impact
- Specific URL, endpoint, or system component
- Step-by-step reproduction guide and proof-of-concept payload
Researchers must not access, modify, download, or delete customer data or disrupt production services during testing.
4. Customer Security Responsibilities
Customers must maintain strong passwords, enable MFA, safeguard API secrets, promptly apply application software updates, and restrict console access to authorized personnel.