1. Our approach
Security is a shared responsibility and part of how we design and operate CatalogIQOS. We use risk-based administrative, technical, and organizational safeguards while continually reviewing our practices as the Service grows.
2. Platform protections
CatalogIQOS uses HTTPS encryption for data in transit, authenticated access, role-based permissions, secure cloud infrastructure, backups, monitoring, and security updates. We limit access according to job responsibilities and use service providers selected with security and reliability in mind. We do not publish sensitive architectural or defensive details.
3. Your responsibilities
Protect your password, use a unique and strong credential, secure your email account and devices, review Workspace membership, grant only necessary permissions, and sign out of shared devices. Never share authentication tokens or API keys. Report suspected compromise immediately.
4. Resilience and backups
We maintain backup and recovery practices designed to support continuity. Backups do not replace your responsibility to maintain appropriate copies of essential source catalog data and exports.
5. Monitoring and updates
We monitor service health and security signals, investigate suspicious activity, and apply security updates based on risk. We may restrict access, rotate credentials, or require account action to protect the platform.
6. Responsible disclosure
If you believe you found a vulnerability, email security@catalogiqos.com with a clear description, affected area, reproduction steps, and impact. Do not access data that is not yours, disrupt service, use social engineering, or publicly disclose an unresolved issue. We will acknowledge good-faith reports and work toward a proportionate resolution.
7. Security incidents
If an incident affects personal information, we will investigate, contain, remediate, and provide notifications as required by applicable law. Security questions may be sent to security@catalogiqos.com.