Pak Books takes student data security seriously. Here is how we approach security, how to report vulnerabilities, and the researchers who've helped us.
Found a bug? Report it responsibly. Scope, timeline, severity matrix, and safe harbor.
Researchers and contributors who've made Pak Books better and safer.
This page exists to give users and researchers confidence in how we handle security — not to publish a map of our internals. We describe our approach at a high level on purpose. If you believe you've found a weakness, please report it through our VDP rather than probing further.
How we protect your data — the measures we take, in plain language.
Pak Books has no user accounts and no password fields. Admin access is granted through rotating, scoped credentials — never stored passwords.
All traffic is encrypted in transit (HTTPS only). Sensitive configuration is stored as encrypted secrets on our hosting platform — never in source code, commits, or build output.
The site is served from a global edge network with built-in DDoS mitigation, automatic TLS, and industry-standard security headers. Our hosting provider is SOC 2 Type II and ISO 27001 certified.
No third-party analytics, no tracking pixels, no behavioral profiling, no advertising. We do not sell or share user data. What you do on Pak Books stays between you and the site.
We layer independent controls — input validation, rate limiting, request authentication, and least-privilege data access — so no single weakness compromises the whole system.
We collect only what we need to operate. There is no payment data (the site is free), no behavioral tracking, and no long-term storage of uploaded files on our own infrastructure.
The specific commitments we make to keep the platform safe.
A conceptual view of how a request travels through Pak Books — without exposing internals.
User (browser)
HTTPS only · Bot protection on public forms · No tracking cookies
Secure edge
TLS termination · Security headers · DDoS protection · Request rate limiting
Application layer
Input validation · Authentication checks · Least-privilege data access
Edge database
User data, books, submissions · SOC 2 + ISO 27001 certified
Temporary uploads
Auto-deleted within days · Nothing retained long-term
Internet Archive
Permanent file storage · Separate account
This is a conceptual overview. We do not publish internal technology choices, database schemas, or the specifics of our authentication mechanisms.
Administrative actions are recorded — full transparency and accountability.
Every administrative action — approvals, edits, deletions, and configuration changes — is recorded in a tamper-evident audit log. This ensures full accountability for any change made to the catalog or platform.
What happens if something goes wrong.
Report received via VDP or internal monitoring. Confirmed within 48 hours.
Fix deployed within 7–90 days depending on severity. Hotfix for critical issues.
Coordinated public advisory after the fix is live. Researcher credited.
For security questions or to report a vulnerability, reach out through our VDP.
Last reviewed: August 2026 · Document version 1.2