Security and Responsible Disclosure
Last updated: 2 September 2026
UCS may use authentication, role-based permissions, audit/security logs, hashing of selected verification values, backups, rate limiting/blocklists, monitoring and incident records. Users must protect passwords, OAuth sessions, resume tokens, certificate codes and devices. Unauthorized access, vulnerability exploitation, credential attacks, scraping of protected data, malware, denial-of-service, signature/certificate manipulation or personal-data extraction is prohibited. Good-faith vulnerability reports may be sent to the UCS contact with reproducible steps and safe evidence; do not access more data than necessary or publish personal data. UCS may preserve logs, reset credentials, restrict access and notify affected persons/providers/authorities where required.
Contact
Questions, privacy requests, complaints and security reports: info@uasurgeons.org. UCS may reasonably verify identity and authority before acting on a request.
Security of membership verification files
Diplomas, certificates, licenses and other membership verification documents should be treated as restricted personal data. Access should follow the need-to-know principle and role-based permissions. UCS may use authenticated access, audit logging, secure transport, controlled storage, backups, malware scanning, download restrictions and other technical safeguards where appropriate.
Verification files should not be placed in a publicly accessible web directory, indexed by search engines or exposed through predictable URLs. Public certificate-verification functionality must not expose private membership application files. Administrative access, downloads, changes of verification status and significant actions may be logged for accountability and incident investigation.
Applicants should upload files only through the official UCS interface, verify that they are using uasurgeons.org, avoid sending unnecessary documents through social media or unsecured channels, protect their account and email access and report suspected unauthorized access.