Security and Privacy Tab

Security & Privacy in AYUDA

AYUDA protects applicant records used in financial assistance workflows. The controls listed below are based on features currently implemented in the system.

Password Hashing Role-Based Access Activity Logs Upload Validation

Implemented Security Controls

These controls are based on current application behavior and code-level implementation.

Password Protection

User and admin passwords are hashed with PBKDF2 via Werkzeug instead of being stored in plain text.

Access Control

Protected routes require authenticated sessions, and role checks restrict admin-only operations.

Audit and Traceability

The system logs key actions such as logins, profile updates, uploads, verification decisions, and status updates.

Input and Upload Safeguards

Uploads use sanitized filenames and extension checks, while forms include validation such as required fields and password rules.

Privacy Commitments

AYUDA uses personal data to support fair and timely financial assistance processing.

Purpose Limitation

Personal data is collected to assess eligibility, process applications, track status, and generate financial assistance reports.

Data Minimization

The platform focuses on profile, eligibility, and application information required for decision support.

Transparent Processing

Applicants receive status updates, while administrators can review logs and decision history.

Role-Limited Access

Sensitive operations are restricted through authentication and role checks for community and admin users.

Deployment Responsibility

Server-level controls such as HTTPS and infrastructure hardening depend on the deployment environment managed by the implementing office.

Questions About Security or Privacy?

For privacy concerns, data correction requests, or account issues, coordinate with your local MSWD office or system administrator.