Pak Books
    Back
    Security Center

    Security

    Pak Books takes student data security seriously. Here is how we approach security, how to report vulnerabilities, and the researchers who've helped us.

    Vulnerability Disclosure

    Found a bug? Report it responsibly. Scope, timeline, severity matrix, and safe harbor.

    Hall of Fame

    Researchers and contributors who've made Pak Books better and safer.

    On responsible disclosure

    This page exists to give users and researchers confidence in how we handle security — not to publish a map of our internals. We describe our approach at a high level on purpose. If you believe you've found a weakness, please report it through our VDP rather than probing further.

    Security Posture

    How we protect your data — the measures we take, in plain language.

    No passwords, ever

    Pak Books has no user accounts and no password fields. Admin access is granted through rotating, scoped credentials — never stored passwords.

    Encryption everywhere

    All traffic is encrypted in transit (HTTPS only). Sensitive configuration is stored as encrypted secrets on our hosting platform — never in source code, commits, or build output.

    Hardened edge hosting

    The site is served from a global edge network with built-in DDoS mitigation, automatic TLS, and industry-standard security headers. Our hosting provider is SOC 2 Type II and ISO 27001 certified.

    Privacy by design

    No third-party analytics, no tracking pixels, no behavioral profiling, no advertising. We do not sell or share user data. What you do on Pak Books stays between you and the site.

    Defense in depth

    We layer independent controls — input validation, rate limiting, request authentication, and least-privilege data access — so no single weakness compromises the whole system.

    Minimal data footprint

    We collect only what we need to operate. There is no payment data (the site is free), no behavioral tracking, and no long-term storage of uploaded files on our own infrastructure.

    Best Practices

    The specific commitments we make to keep the platform safe.

    • No payment data — Pak Books is completely free, no transactions ever occur
    • No accounts required to read or download books
    • Personally identifying information is kept to the minimum needed for a submission
    • Temporary uploads are auto-deleted within days — nothing retained long-term on our servers
    • Permanent files are hosted on the Internet Archive, not on our infrastructure
    • Admin actions are fully audited and logged for accountability
    • Sensitive endpoints are rate-limited to resist abuse and brute force
    • Bot protection is enabled on public submission forms
    • Failed administrative access attempts are tracked and reviewed
    • Security reviews are performed before major changes ship to production

    Security Architecture

    A conceptual view of how a request travels through Pak Books — without exposing internals.

    1

    User (browser)

    HTTPS only · Bot protection on public forms · No tracking cookies

    2

    Secure edge

    TLS termination · Security headers · DDoS protection · Request rate limiting

    3

    Application layer

    Input validation · Authentication checks · Least-privilege data access

    4a

    Edge database

    User data, books, submissions · SOC 2 + ISO 27001 certified

    4b

    Temporary uploads

    Auto-deleted within days · Nothing retained long-term

    4c

    Internet Archive

    Permanent file storage · Separate account

    This is a conceptual overview. We do not publish internal technology choices, database schemas, or the specifics of our authentication mechanisms.

    Accountability & Audit

    Administrative actions are recorded — full transparency and accountability.

    Admin Audit Log

    Every administrative action — approvals, edits, deletions, and configuration changes — is recorded in a tamper-evident audit log. This ensures full accountability for any change made to the catalog or platform.

    Incident Response

    What happens if something goes wrong.

    1

    Identify

    Report received via VDP or internal monitoring. Confirmed within 48 hours.

    2

    Remediate

    Fix deployed within 7–90 days depending on severity. Hotfix for critical issues.

    3

    Disclose

    Coordinated public advisory after the fix is live. Researcher credited.

    Security questions?

    For security questions or to report a vulnerability, reach out through our VDP.

    Read the VDPHall of Fame

    Last reviewed: August 2026 · Document version 1.2

    SecurityVDPHall of Fame

    © 2026 Pak Books — Free knowledge for Pakistan 🇵🇰

    Hosted by Internet Archive
    Made byUbaid Ur Rehman