Security
How this website and your payment details are protected.
Effective from 10 September 2026
Website security
- The entire website is served over HTTPS with a valid TLS certificate, so traffic between your browser and our server is encrypted.
- The administrative area is protected by individual accounts. Passwords are stored only as one-way cryptographic hashes and are never recoverable in readable form.
- Donor and enquiry records are accessible only to authorised Prajna staff after signing in, and are never exposed through public pages of the website.
Payment security
- Card, UPI and netbanking credentials are entered directly into Razorpay's PCI-DSS compliant hosted checkout and never reach Prajna's servers.
- Prajna does not store card numbers, CVV codes, UPI PINs or netbanking passwords in any form.
- Payment confirmations are verified server-side against the gateway's cryptographic signature before a donation is recorded, so a browser redirect alone can never mark a donation as received.
Your part
- Donate only through pages served from our own domain, and check for the padlock in your browser's address bar.
- Prajna will never ask you for your card CVV, UPI PIN, netbanking password or an OTP by phone, email or message. Treat any such request as fraudulent.
- If you are asked to donate to an account other than the one published on our donate page, stop and contact us first.
Reporting a security concern
If you believe you have found a security weakness in this website, please write to prajnacare@gmail.com with enough detail for us to reproduce it. We ask that you give us a reasonable opportunity to fix the issue before disclosing it publicly, and that you do not access or modify data belonging to anyone else while investigating.
