1. Principles
We use data minimization, access controls, separation of duties, backups and risk-based safeguards.
2. Responsible disclosure
Report vulnerabilities to security@ezconnect.me. Do not access other users’ data, disrupt services, extort, or publish exploitable details before a reasonable remediation opportunity.
3. Sensitive links and tokens
Sensitive operational links should be temporary, revocable and designed to reduce exposure through query strings, logs, cache, analytics or referrers. Private views should not be indexed.
4. Incidents
We investigate incidents reasonably and make notifications required by applicable law based on the data and risk involved.
5. Limits
This policy does not authorize destructive testing, social engineering, unauthorized access or harm to third parties. No system can promise absolute security.