Enterprise GRC Platform
Security Policy
Our commitment to security and responsible vulnerability disclosure.
Security at Tyndora
How we protect your data and systems.
Security is fundamental to everything we build at Tyndora. We implement industry-leading security practices across our platform, operations, and processes to ensure the confidentiality, integrity, and availability of customer data.
Key Security Measures
- • AES-256 encryption for data at rest
- • TLS 1.3 encryption for data in transit
- • Multi-factor authentication and single sign-on
- • Role-based access control and audit logging
- • Regular penetration testing and security audits
- • SOC 2 Type II compliance certification
- • Incident response procedures and 24/7 monitoring
Reporting Security Vulnerabilities
Responsible disclosure guidelines.
We welcome responsible security research and reports from security professionals and ethical hackers. If you discover a security vulnerability, please report it to our security team.
Reporting a Vulnerability
Email: sales@tyndoragrc.net
Please include a detailed description of the vulnerability, steps to reproduce, and potential impact.
Responsible Disclosure Process
- 1. Report: Submit your finding via email to sales@tyndoragrc.net
- 2. Acknowledge: We will acknowledge receipt within 24 hours
- 3. Investigate: Our security team will investigate the vulnerability
- 4. Fix: We will develop and test a patch (typically within 30 days)
- 5. Disclose: We will coordinate with you on responsible public disclosure
- 6. Credit: We will acknowledge your contribution (if desired)
What We Ask of Researchers
Guidelines for responsible disclosure.
- • Give us reasonable time to patch before public disclosure
- • Avoid testing in production environments without authorization
- • Do not access, modify, or delete data beyond what's necessary to demonstrate the vulnerability
- • Do not disrupt service or interfere with other users
- • Keep the vulnerability confidential until we publicly release a fix
- • Do not demand payment or compensation (though we may offer recognition)
What You Can Expect
Our commitment to researchers.
- • Transparent communication throughout the process
- • Good-faith efforts to patch all confirmed vulnerabilities
- • Public acknowledgment of your contribution (if desired)
- • Protection under responsible disclosure guidelines
- • Clear timeline for patching and disclosure
Bug Bounty Program
Future program for security researchers.
We are currently evaluating a formal bug bounty program. In the meantime, please use our responsible disclosure process to report vulnerabilities. We recognize the importance of security research and are committed to working with the community.