Demo environment — sample data
WORLD KBNWorld Federation of Martial Arts
Apply for ranking

Security & vulnerability disclosure

How the platform is protected and how to report a security vulnerability responsibly.

Last updated
Version
2.0
Effective
28 September 2026
Operator
KBN World Federation of Martial Arts
All legal documents
Draft for legal review. These documents are a detailed template written for how this platform actually works, but they have not yet been reviewed by a qualified UK solicitor. KBN must have them reviewed before relying on them, in particular the limitation of liability, the rules for minors, the handling of health and anti-doping (special category) data and the roles of national branches in other countries. Items marked [to be confirmed] are details KBN has not yet supplied.

1. How we protect the Service

  • All traffic is encrypted with HTTPS, with HTTP Strict Transport Security (HSTS) and security headers including a Content Security Policy.
  • Passport and national ID numbers, KBN Social dates of birth and two-factor secrets are encrypted in the database. Passwords are stored only as salted hashes.
  • Access is controlled by role and permission on the server. Branch officers can access only their own country's records; this is enforced by policies and query scopes and covered by automated tests.
  • Administrators can use time-based one-time password (TOTP) two-factor authentication; it is required for super administrators outside demo mode.
  • Uploads are stored on private storage and served only through access-checked routes or signed, time-limited links. A virus-scanning hook runs before applicant uploads are stored; the scanner connected to it is [to be confirmed].
  • Login, verification, application, messaging, reporting and AI endpoints are rate-limited.
  • Every state change (stage changes, result decisions, multiplier changes, licence actions, certificate issue, role and settings changes) is recorded in an audit log with who, when and before/after values.
  • Nightly backups are taken and kept as described in the Data retention schedule.
  • The servers use a firewall allowing only web and administrative access, non-root deploy users with SSH keys, automatic security updates and brute-force protection.
↑ Contents

2. Reporting a vulnerability

2.1If you believe you have found a security vulnerability, please report it to holdingkbn@gmail.com with the subject "Security". Include a description, the steps to reproduce it, the affected URL or feature and your contact details. Please do not include other people's personal data.

2.2We will acknowledge your report within 5 working days, keep you informed, and tell you when it is fixed. We are happy to credit you if you wish. We do not currently run a paid bug bounty.

↑ Contents

3. Good-faith research

3.1We will not take legal action against research that is carried out in good faith and in line with this policy. Please:

  • Only test against your own accounts, or the demo accounts on a site marked "Demo environment".
  • Not access, change or delete data that is not yours; stop and report immediately if you encounter personal data.
  • Not carry out denial-of-service, spam, social-engineering or physical attacks, or use automated scanners at a volume that degrades the Service.
  • Give us reasonable time to fix the issue before disclosing it publicly.
↑ Contents

4. Data breaches

4.1If a personal data breach occurs we will contain it, assess the risk, notify the Information Commissioner's Office within 72 hours where required, and tell affected people without undue delay where the breach is likely to result in a high risk to them.

↑ Contents

5. Your part

5.1Use a strong, unique password, enable two-factor authentication where available, log out on shared devices, and never share your login. KBN will never ask for your password by e-mail or message.

↑ Contents

Questions about this document: holdingkbn@gmail.com. Where this document is translated, the English version prevails to the extent permitted by law. Version 2.0, last updated 28 September 2026. Printed copies may be out of date; the version at worldkbn.com/legal/security applies.