How we protect the website and how to report security concerns
Effective date: 13 Aug 2026
Kisauni Islamic Institute takes website security seriously. This Security Policy explains the expected use of the website and how security concerns should be reported.
We use reasonable safeguards to protect the website, CMS, uploaded files, and submitted forms. These may include access controls, password-protected administration pages, file upload validation, server configuration, and routine maintenance.
CMS access is restricted to authorised school staff or approved administrators. Admin users should use strong passwords, keep login details confidential, and sign out after using shared devices.
Website forms validate required fields before submission. Image uploads are limited by file type and size. SVG uploads are screened for unsafe script patterns, but uploaded files should still be reviewed by authorised administrators.
You must not attempt to access private areas, bypass authentication, scan or attack the website, upload malicious files, exploit vulnerabilities, spam forms, or interfere with normal website operation.
If you discover a security issue, please report it responsibly by emailing administration@kisauniislamicinstitute.co.ke. Include a clear description, affected page, steps to reproduce, and screenshots if helpful.
Please give the school reasonable time to investigate and fix reported issues before making details public. Do not access, modify, delete, download, or disclose personal information or school data while testing or reporting an issue.
No website can be guaranteed to be completely secure. We will continue improving the website's security practices as risks, technology, and school needs change.