Security Policy

How we protect member data and how to report a vulnerability.

Last updated:

How we protect your account

  • Passwords are hashed with bcrypt (salted, one-way) — never stored in plain text
  • Authenticated access uses signed, expiring session tokens (JWT)
  • Role-based access controls separate member and president (admin) capabilities
  • Security response headers (nosniff, frame protection, referrer policy) are applied
  • Inactive or removed accounts immediately lose portal access

Your role in security

  • Use a strong, unique password you do not reuse elsewhere
  • Sign out on shared devices
  • Never share your credentials; MLA staff will never ask for your password
  • Report suspicious messages or activity promptly

Responsible disclosure

We welcome reports from security researchers and members. If you believe you have found a vulnerability:

✉️ Email security@mercerlandlords.org with details and steps to reproduce.
Please give us reasonable time to investigate and remediate before public disclosure, and do not access or modify data that is not yours.

We will acknowledge your report, keep you informed of progress, and credit researchers who wish to be recognized.

Scope

This policy covers the Association's website and member portal. Third-party services linked from our site are governed by their own policies; see our Link Policy.

Incident response

In the event of a data incident affecting your information, we will notify affected members and applicable authorities as required by law.