Security

Security at Crystal Magnate

We take security seriously. We welcome responsible disclosure of potential vulnerabilities and misuse concerns involving our systems, customer data, or related services.

How to report a security vulnerability

If you believe you have discovered a security vulnerability or suspected misuse of data, please contact us directly using the email below. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond.

Security contact

[email protected]

What you can expect

  • Reports are acknowledged within 2 business days whenever possible.
  • We investigate reports promptly and coordinate remediation with the appropriate internal teams.
  • We may ask for additional detail or proof of concept to validate the report.
  • We will keep you informed about progress while protecting sensitive information.

Response and incident handling

Incident investigation process

Once a report is received, we assess severity, validate the issue, contain potential exposure, and determine the appropriate remediation path. If the report concerns suspected misuse of data, we may escalate the issue to a formal incident review.

Data-breach notification process

If a confirmed or likely security incident affects customer data, we will assess the impact, contain the issue, and notify affected parties and relevant stakeholders as required by law and our internal incident procedures.

Responsible disclosure

We support responsible disclosure and will not pursue legal action against individuals who report vulnerabilities in good faith and follow the process above. We ask that reports be made in a way that avoids unnecessary risk to our users, systems, or data.

This policy is intended to support the safe and transparent reporting of security issues and suspected misuse of data in line with applicable security and data-protection obligations.