Security

Security policy and vulnerability disclosure

If you have found a security vulnerability in cloudtechforce.com or in a service we operate, email security@cloudtechforce.com with the details. We acknowledge reports within two business days, do not pursue legal action against good-faith research that follows this policy, and credit reporters who want to be credited.

Last reviewed 2026-09-05 by Muhammad Ali, CTO.

Scope

  • cloudtechforce.com and its subdomains
  • Systems CloudTechForce operates on behalf of clients, where the client has authorised testing in writing

Out of scope: denial-of-service testing, social engineering of staff or clients, physical access, and any testing of client systems without the client's written authorisation.

How to report

  1. Email security@cloudtechforce.com with a description, steps to reproduce, affected URL or system, and any proof-of-concept.
  2. We acknowledge within two business days and give you a point of contact.
  3. We aim to fix confirmed high-severity issues within 14 days and others within 90 days, and we tell you when it is done.
  4. Please give us reasonable time to fix an issue before disclosing it publicly.

Our commitments

  • We will not take legal action against researchers who act in good faith, avoid privacy violations and data destruction, and follow this policy.
  • We do not run a paid bounty programme at this time.
  • We will credit reporters here, with their permission. {#thanks}

Machine-readable

This policy is referenced by /.well-known/security.txt per RFC 9116.

On this page

Talk to an engineer, not a salesperson

Book a 15-minute call, or send us your current IT invoice and we will tell you what we would change. No obligation.

on shift now
help desk 24/7