Security & Trust

How MyNikkahOnline protects your data, your privacy, and your account against cyber threats.

🔒 HTTPS / TLS Encrypted
🛡️ CSRF Protected
🚫 Rate Limiting Enabled
🔑 Bcrypt Password Hashing
🕵️ Audit Logs Active
📧 OTP Email Verification

Core Security Layers

🔐

Encrypted Passwords

Passwords are never stored in plain text. We use industry-standard one-way hashing (bcrypt) with a unique salt per user. Even our own team cannot read your password.

📧

OTP Email Verification

Every new account must verify their email with a one-time password (OTP) before accessing the platform. OTPs expire within 10 minutes and are single-use.

🔒

HTTPS / TLS Encryption

All communication between your browser and our servers is encrypted in transit using TLS. Your personal data, messages, and session cookies cannot be read by third parties on the network.

🛡️

CSRF Protection

Every form submission is protected with a Cross-Site Request Forgery (CSRF) token. This prevents malicious websites from performing actions on your behalf without your knowledge.

🚦

Rate Limiting

Login, registration, OTP, and other sensitive endpoints are rate-limited. This blocks automated brute-force attacks and credential-stuffing bots from hammering our API.

🚫

Injection Prevention

All database queries use parameterised statements — never raw string concatenation. This fully prevents SQL injection attacks. User-submitted HTML is also escaped before display to block XSS.

🍪

Secure Session Cookies

Session cookies are marked HttpOnly (not accessible to JavaScript) and SameSite=Lax (no cross-site sending). In production they are also Secure (HTTPS-only).

↩️

Open Redirect Blocked

After login, we validate the redirect destination. External URLs and protocol-relative URLs (e.g. //evil.com) are rejected — you will only ever be redirected within MyNikkahOnline.

Account & Access Security

Data Privacy & Moderation

Infrastructure & Response Headers

🔍 Found a Vulnerability?

We take security seriously. If you discover a bug or potential security issue, please report it responsibly to our team. We respond to all reports within 48 hours.

Report a Security Issue
Closed Beta: MyNikkahOnline is currently in a demonstration & testing phase. No premium fees are charged. Users must independently verify matches before any personal interaction.  |  Legal & Compliance
WhatsApp