Cyber Security & Responsible Disclosure
Version 1.0 · Last updated: 21 July 2026
1. Security controls
- Encryption of data in transit (TLS 1.2+) and at rest for stored user data.
- Role-based access control, least privilege and audit logging for administrators.
- Managed cloud infrastructure with monitoring, rate-limiting and DDoS protection.
- Automated malware scanning on user-uploaded attachments.
- Continuous dependency scanning and periodic security review.
2. User responsibilities
Use strong, unique passwords, enable available multi-factor authentication and notify us immediately at security@coldmatchgroup.com if you suspect unauthorised access to your account.
3. Responsible disclosure
If you believe you have found a security vulnerability, please report it to security@coldmatchgroup.com with a description, reproduction steps and any relevant evidence. We ask researchers to:
- Give us reasonable time to investigate and remediate before public disclosure.
- Avoid privacy violations, service disruption and data exfiltration beyond what is strictly necessary to demonstrate the issue.
- Not access, modify or delete data belonging to other users.
- Comply with all applicable laws.
4. Safe harbour
We will not pursue legal action against researchers who report vulnerabilities in good faith and in accordance with this policy.
5. Out of scope
Denial-of-service testing, social engineering of employees or suppliers, physical attacks, and issues affecting outdated browsers or unsupported third-party services are out of scope.
Related legal documents
- Terms of Service · v3.0
- Privacy Policy · v2.2
- Cookie Policy · v1.4
- General Disclaimer · v2.1
- Legal Notice · v1.3
- RFQ Terms · v1.0
- Buyer Terms · v1.0
- Supplier Terms · v1.0
Governing law: Republic of Cyprus · Exclusive jurisdiction: the competent courts of the Republic of Cyprus, without prejudice to any non-derogable rights available to users under mandatory local law. Contact: legal@coldmatchgroup.com.
