Security Policy
This Security Policy explains CMPROM's public security posture for the website, contact forms, client-facing areas and related business workflows.
1. Security Objectives
CMPROM aims to reduce operational risk through controlled access, secure form handling, validation, logging, least-privilege administration and documented responsibilities.
2. Controls
- CSRF protection and input validation for forms;
- prepared database statements where data is queried or stored;
- role-based access for administrative and client areas;
- secure session handling where login features are enabled;
- audit-friendly logs for important operations;
- controlled downloads and file handling where supported;
- backup and recovery routines where included in the commercial agreement.
3. Shared Responsibility
Clients remain responsible for credentials, user approvals, lawful content, DNS, hosting decisions, third-party services and compliance obligations within their own operations.
4. Vulnerability Reports
Security concerns should be reported responsibly to contact@cmprom.com. Do not access, modify, delete or disclose data that is not yours.
5. No Absolute Guarantee
No digital system can be guaranteed to be uninterrupted, error-free or immune from all security risks.