Trust
Security
How we protect your account and your documents, how to spot a fake payment request, and how to tell us if you find a problem.
Last reviewed: 1 September 2026
Protecting your account
- Use a password you use nowhere else, at least 10 characters.
- We will never ask for your password, a one-time code, or card details in a message.
- If a message asks you to move a conversation off the platform to complete a payment, it is not from us. Report it.
How to verify a payment request
Before you pay anyone, anything, check all four:
- Who is charging. Every invoice in your portal names the issuer. Admission.ly does not charge students a platform fee, so an invoice from us for “applying” is a red flag.
- Where the request came from. Log in and look at your invoices directly rather than following a link in an email.
- The bank details. Institutions publish their payment details on their own site. Compare them. Details that arrive by message and differ from the published ones are the classic study-abroad fraud.
- The refund terms. Get them in writing before paying.
How we protect documents
- Uploads are stored outside the public web root under opaque keys.
- There is no shareable link to a document. Every download goes through an authorised route that re-checks your entitlement against the owning application on each request.
- Files are always served as downloads, never rendered inline on our origin.
- Passwords are stored only as bcrypt hashes.
- Sessions are httpOnly, SameSite cookies, signed and time-limited.
Reporting a vulnerability
Email security@admission.ly with enough detail to reproduce the issue. Please:
- give us reasonable time to fix it before disclosing publicly;
- do not access, modify or delete data belonging to anyone else;
- do not run denial-of-service or automated scanning against production.
We will acknowledge within 24 business hours, keep you updated, and credit you if you would like that.