If we suffer a breach
Where a personal data breach is likely to result in a risk to affected people, we notify the relevant
authority within the period the law requires and tell affected customers without undue delay. You will
be told what happened, what data was involved, what we have done about it and what you should do.
We will not describe an incident as a “security event” and hope you do not ask further.
If you find a vulnerability
Report it to
security@litoraai.com. We will not
pursue researchers who act in good faith, do not access or exfiltrate other users' data, and give us a
reasonable opportunity to fix the problem before disclosing it.
If you want to test the platform actively, ask first and we will usually say yes. Testing without
permission is a breach of the acceptable use policy, and we would
rather give permission than deal with it that way.
What we do not claim
No system is perfectly secure and we will not pretend otherwise. We hold no security certification at
present, and we would rather say so than imply one. What this page describes is what we actually do; if
your firm requires a formal assurance report before it can use a processor, tell us what standard you
need and we will tell you honestly whether we meet it.