Security
Security policy and vulnerability disclosure
If you have found a security vulnerability in cloudtechforce.com or in a service we operate, email security@cloudtechforce.com with the details. We acknowledge reports within two business days, do not pursue legal action against good-faith research that follows this policy, and credit reporters who want to be credited.
Last reviewed 2026-09-05 by Muhammad Ali, CTO.
Scope
- cloudtechforce.com and its subdomains
- Systems CloudTechForce operates on behalf of clients, where the client has authorised testing in writing
Out of scope: denial-of-service testing, social engineering of staff or clients, physical access, and any testing of client systems without the client's written authorisation.
How to report
- Email security@cloudtechforce.com with a description, steps to reproduce, affected URL or system, and any proof-of-concept.
- We acknowledge within two business days and give you a point of contact.
- We aim to fix confirmed high-severity issues within 14 days and others within 90 days, and we tell you when it is done.
- Please give us reasonable time to fix an issue before disclosing it publicly.
Our commitments
- We will not take legal action against researchers who act in good faith, avoid privacy violations and data destruction, and follow this policy.
- We do not run a paid bounty programme at this time.
- We will credit reporters here, with their permission. {#thanks}
Machine-readable
This policy is referenced by /.well-known/security.txt per RFC 9116.
Talk to an engineer, not a salesperson
Book a 15-minute call, or send us your current IT invoice and we will tell you what we would change. No obligation.
on shift now
help desk 24/7
help desk 24/7