Security Policy
Last updated: 30 July 2026
ThesisPublisher.my takes the security of author, reviewer and reader data seriously. This page describes the measures in place and how to report a problem.
1. Payment security
We do not store, process or transmit card numbers. Payment is handled entirely by our gateway partner within their own secure checkout. Every payment we settle is verified by a cryptographic signature before access is granted or a registration is confirmed, so a payment result cannot be forged by a browser.
2. Data in transit
All traffic to this site is served over HTTPS/TLS. Submissions, manuscripts and personal data are encrypted in transit.
3. Account security
in plain text and never emailed to you.
active sessions when used.
automated guessing.
- Passwords are stored only as salted bcrypt hashes; they are never recoverable
- Password-reset links are single-use, expire after one hour, and invalidate all
- Sign-in, registration and password-reset endpoints are rate limited to frustrate
4. Access control
The platform enforces role-based access: administrators, editors, reviewers and authors each see only what their role permits. Editorial permissions are scoped to the specific journals a person is assigned to — holding an editor account does not grant access to another journal's material.
5. Confidential material
Unpublished manuscripts, peer-review reports, submitted CVs and identification documents are stored outside any publicly readable location and are served only through access-controlled endpoints. Subscription-only content is gated on every request rather than by hiding a link.
6. Peer-review confidentiality
Manuscripts under review are disclosed only to assigned editors and reviewers. Reviewer identities are protected according to each journal's stated peer-review model.
7. Backups and continuity
Databases and uploaded files are backed up on a regular schedule. Backups are retained so that a recent, consistent restore point is always available.
8. Reporting a vulnerability
If you believe you have found a security vulnerability, email support@thesispublisher.my with the subject line "Security". Please include enough detail to reproduce the issue.
We ask that you give us a reasonable opportunity to fix the problem before public disclosure, and that you avoid accessing, altering or deleting data belonging to others while investigating. We will acknowledge your report within 2 business days and keep you informed until it is resolved. We do not take legal action against researchers who report in good faith under these terms.
9. Incident notification
If a breach affects your personal data, we will notify affected users and the relevant supervisory authority as required by applicable law, without undue delay.
10. Contact
ThesisPublisher.my — Email: support@thesispublisher.my
