ALTIVOR INSTITUTE welcomes good-faith vulnerability reports submitted to contact@altivor.institute. Unauthorised security testing, penetration testing or active exploitation of vulnerabilities is strictly prohibited and may constitute a criminal offence.
This Security Policy (the "Policy") sets out the framework governing the protection of systems, data and infrastructure associated with the operation of the platform at ALTIVOR INSTITUTE accessible at altivor.institute (the "Platform").
ALTIVOR INSTITUTE is committed to maintaining appropriate and proportionate security measures designed to protect users and the integrity of the Platform. This Policy describes the principles and controls applied in pursuit of that objective.
This Policy has been established to:
Security controls implemented by ALTIVOR INSTITUTE are applied to protect the following assets and systems:
ALTIVOR INSTITUTE deploys technical security measures appropriate to the nature of the Platform. These may include:
The specific technical measures applied may evolve over time in response to changes in the threat landscape, technology and applicable best practices. ALTIVOR INSTITUTE does not disclose the detailed configuration of its security infrastructure.
In addition to technical controls, ALTIVOR INSTITUTE implements organisational procedures designed to:
Users bear primary responsibility for the security of their own account. Each user is required to:
ALTIVOR INSTITUTE will never request a user's password via email or any other unsolicited communication. Users should treat any such request as a phishing attempt and report it immediately.
All personal data collected and processed in connection with the Platform is handled in accordance with the Privacy Policy and applicable data protection legislation, including the General Data Protection Regulation (GDPR) where applicable.
Security measures applied to personal data are designed to be appropriate to the risk presented by the nature of the data processed and the context in which it is held.
In the event of a security incident, ALTIVOR INSTITUTE will take prompt and appropriate steps to:
The investigation and response to security incidents will be conducted in accordance with ALTIVOR INSTITUTE's internal incident response procedures. Where a personal data breach has occurred, ALTIVOR INSTITUTE will fulfil its notification obligations under applicable data protection law.
ALTIVOR INSTITUTE may engage third-party technology service providers in connection with the operation of the Platform. Where such providers are granted access to Platform systems or user data, they are required to maintain security standards consistent with this Policy and applicable law.
ALTIVOR INSTITUTE conducts reasonable due diligence in the selection of third-party service providers and requires contractual commitments regarding data security where appropriate. A list of third-party data processors is set out in the Privacy Policy.
ALTIVOR INSTITUTE takes reasonable steps to maintain the availability and reliability of the Platform. However, ALTIVOR INSTITUTE does not warrant uninterrupted access to the Platform and accepts no liability for temporary unavailability resulting from:
Where planned maintenance is expected to cause material service disruption, ALTIVOR INSTITUTE will endeavour to provide advance notice through the Platform where reasonably practicable.
Notwithstanding the security measures implemented by ALTIVOR INSTITUTE, no information technology infrastructure can be guaranteed to be entirely free from risk. ALTIVOR INSTITUTE does not warrant that the Platform will be immune from all security threats or vulnerabilities.
ALTIVOR INSTITUTE accepts no liability for losses or damage arising from security incidents caused by factors outside its reasonable control, including but not limited to actions of malicious third parties, vulnerabilities in third-party software or hardware, or failures in user-side security practices. Liability is limited as set out in the Terms & Conditions.
ALTIVOR INSTITUTE operates a responsible disclosure programme. Users or security researchers who identify a potential vulnerability in the Platform are encouraged to report it in accordance with the following guidelines:
Reports should include a description of the vulnerability, the potential impact, and where possible, steps to reproduce the issue. ALTIVOR INSTITUTE will investigate all credible reports and, where a valid vulnerability is confirmed, will endeavour to address it in a timely manner.
Unauthorised security testing is strictly prohibited. Any form of active probing, scanning, penetration testing, or exploitation of the Platform or its infrastructure without the prior written consent of ALTIVOR INSTITUTE is forbidden and may constitute a criminal offence under applicable law.
ALTIVOR INSTITUTE reserves the right to update this Policy at any time in response to changes in technology, applicable law, or the threat environment. Amended versions will be published on the Platform and will take effect upon publication. Continued use of the Platform following any amendment constitutes acceptance of the revised Policy.
This Policy is issued by ALTIVOR INSTITUTE and is to be read in conjunction with the Privacy Policy, Anti-Fraud Policy, Acceptable Use Policy and Terms & Conditions.
For vulnerability reports and security concerns: contact@altivor.institute