Security
How MEND SOLUTION products and updone.in protect your account and your information, and how to report a security problem.
- Last updated
- 6 October 2026
- Applies to
- updone.in & all products
- Run by
- MEND SOLUTION
- Questions
- info@updone.in
01
Secure sign-in
Our products sign you in through established authentication services such as Supabase Auth and Google sign-in, so passwords are never stored in plain text. When you sign in with Google, your password stays with Google.
02
Access by role
Each product shows people only what their role allows. For example, a student sees their own records, a faculty member sees the students assigned to them, a department sees its own items, and admins manage their own organisation. Access rules are enforced on the server, not just hidden on screen.
03
Protecting your data
- Every connection to our products and this website is encrypted with HTTPS.
- Uploaded files are kept in private storage and opened through short-lived, signed links.
- Each organisation’s information is kept apart from every other organisation’s.
- Our service providers are established platforms with their own security programmes — see the Privacy Policy.
04
This website
updone.in has no logins or forms. It is served over HTTPS only with HSTS, a strict Content Security Policy, protection against being framed by other sites, and browser features it does not need — camera, microphone, location — switched off.
05
Keeping your account safe
- Use a strong password you do not use anywhere else, or sign in with Google.
- Sign out on shared computers.
- Tell your organisation’s admin, or write to info@updone.in, if you think someone else has used your account.
06
Reporting a vulnerability
If you find a security problem in updone.in or in any MEND SOLUTION product, please e-mail info@updone.in. Include:
- the address or product affected;
- the steps to reproduce the problem;
- what an attacker could do with it.
We will acknowledge valid reports and keep you informed while we fix them.
07
While you test
Please act in good faith:
- do not access, change or delete other people’s data — use your own test account;
- do not disrupt the service for other users;
- give us reasonable time to fix a problem before making it public.
08
security.txt
Our contact details for security reports are also published in the standard machine-readable format at updone.in/.well-known/security.txt.