Home · Data security
Data security
We manage data that matters to our members: the studbook, show entries, the Judges' School records. Here is, briefly and honestly, what we do to keep it safe.
What we do
- Encryption in transit. The whole site runs exclusively over HTTPS.
- Code-based access with rate limiting. Internal areas (registry office, courses platform, administration) open only with individual codes; repeated failed attempts are blocked automatically, and codes can be revoked at any time.
- Secrets live only on the server. The verification keys for codes and sessions never reach the public pages.
- Audit trail. Sensitive registry operations (issuing, changes, deletions) are recorded with author and date.
- Encrypted backups. Records have encrypted backup copies (AES-256), kept separately from the working systems; restoration is tested.
- Data minimisation. We ask only for what the purpose requires, and public pages show only what must be public (e.g. owners' contact details do not appear in the web version of the catalogue). See also the privacy policy andpersonal data requests.
- Up-to-date software. Components are updated regularly and the system is checked periodically for known vulnerabilities.
What we do not promise
No organisation can guarantee absolute security. What we do promise is that we take the measures above seriously, fix what is found as a priority, and, should an incident affect anyone's data, notify them as the law requires.
Found a security issue?
Write to
contact@cfc-royal.ro with the subject "Security". Describe what you found and how to reproduce it; please do not access other people's data and do not disclose the issue publicly before we have had a chance to fix it. We reply as fast as we can, and we thank you — good-faith reports help everyone.