Skip to content
admission.ly

Trust

Security

How we protect your account and your documents, how to spot a fake payment request, and how to tell us if you find a problem.

Last reviewed: 1 September 2026

Protecting your account

  • Use a password you use nowhere else, at least 10 characters.
  • We will never ask for your password, a one-time code, or card details in a message.
  • If a message asks you to move a conversation off the platform to complete a payment, it is not from us. Report it.

How to verify a payment request

Before you pay anyone, anything, check all four:

  • Who is charging. Every invoice in your portal names the issuer. Admission.ly does not charge students a platform fee, so an invoice from us for “applying” is a red flag.
  • Where the request came from. Log in and look at your invoices directly rather than following a link in an email.
  • The bank details. Institutions publish their payment details on their own site. Compare them. Details that arrive by message and differ from the published ones are the classic study-abroad fraud.
  • The refund terms. Get them in writing before paying.

How we protect documents

  • Uploads are stored outside the public web root under opaque keys.
  • There is no shareable link to a document. Every download goes through an authorised route that re-checks your entitlement against the owning application on each request.
  • Files are always served as downloads, never rendered inline on our origin.
  • Passwords are stored only as bcrypt hashes.
  • Sessions are httpOnly, SameSite cookies, signed and time-limited.

Reporting a vulnerability

Email security@admission.ly with enough detail to reproduce the issue. Please:

  • give us reasonable time to fix it before disclosing publicly;
  • do not access, modify or delete data belonging to anyone else;
  • do not run denial-of-service or automated scanning against production.

We will acknowledge within 24 business hours, keep you updated, and credit you if you would like that.