Security boundaries
NursingLicenseBoards.com does not process license applications, renewal payments, portal credentials, Social Security numbers, fingerprints, background-check files, or patient information. Do not submit those materials through the contact form or administrator system.
Application controls
The package uses a one-time administrator setup token, password hashing, login throttling, session regeneration, HTTP-only and SameSite session cookies, POST-only logout, CSRF protection, output escaping, contact-form throttling, a honeypot, and sensitive-number rejection. Data, cron, SQL, audit, submission, session, and rate-limit files are placed under server access controls.
Transport and browser controls
Production requests are redirected to the preferred HTTPS host. Apache headers restrict framing, MIME sniffing, referrer leakage, browser permissions, cross-origin opener behavior, scripts, forms, and embedded objects. Hosting configuration must allow the packaged .htaccess rules.
Reporting a vulnerability
Use the contact form for a concise security report and provide the affected public URL, observed behavior, and safe reproduction steps. Do not exploit the issue further, access another person's data, disrupt service, or include secrets and regulated personal information.
Response and retention
Administrators should preserve only the minimum evidence needed to investigate, remove resolved reports within the privacy-policy retention period, rotate exposed credentials, and apply hosting and dependency updates promptly.