Cafiyn Innovations LLP ("Cafiyn", "Company", "we", "our", or "us") is committed to providing secure, reliable, lawful, and trustworthy services for customers, partners, visitors, and users.
This Acceptable Use and Responsible Security Disclosure Policy ("Policy") establishes:
This Policy applies to all users, customers, visitors, contractors, partners, and security researchers interacting with Cafiyn systems and services.
This Policy applies to:
This Policy supplements and does not replace the Terms of Service, Privacy Policy, Security Policy, or other applicable agreements.
Users may access and use the Services solely for lawful business and personal purposes consistent with:
Users must use the Services responsibly and in a manner that does not adversely affect service availability, security, performance, other users, or Cafiyn operations.
Users shall not engage in activities that are unlawful, harmful, deceptive, fraudulent, abusive, or disruptive.
Prohibited activities include but are not limited to:
Users shall not:
Any attempt to gain unauthorized access may result in immediate suspension and legal action where appropriate.
Users shall not introduce, distribute, transmit, deploy, or facilitate:
Users shall not attempt to compromise the security, integrity, or availability of the Services.
Users shall not:
Activities that negatively affect platform performance may be restricted or blocked.
Users shall not:
Users are responsible for ensuring their activities comply with applicable privacy laws.
Users shall not use the Services to:
Any use of the Services for abusive communications is prohibited.
Users shall not:
Users remain responsible for ensuring they possess rights to any materials they submit to Cafiyn. See the Copyright and Intellectual Property Policy for infringement reporting.
Users are expected to:
Users are responsible for activity occurring under their accounts.
To protect the Services and users, Cafiyn may monitor activity reasonably necessary to:
Monitoring shall be conducted in accordance with applicable law and our Privacy Policy.
Cafiyn welcomes reports of potential security vulnerabilities affecting systems owned or operated by Cafiyn.
Security vulnerabilities should be reported to infosec@cafiyn.com with the subject line "Security Vulnerability Report".
Researchers are encouraged to provide:
Providing detailed information helps expedite investigation.
Researchers should:
Testing should be limited to the minimum activity necessary to demonstrate the existence of a vulnerability.
Cafiyn supports good-faith security research conducted responsibly and within the limits of this Policy.
Researchers may identify and report vulnerabilities affecting systems owned and operated by Cafiyn.
Authorized research does not include activities that:
Unless expressly authorized in writing by Cafiyn, researchers shall not:
If customer information is encountered accidentally, researchers must:
Researchers must not retain customer data.
Where individuals act in good faith and comply with this Policy, Cafiyn generally considers such activity to be legitimate security research and will not pursue legal action for accidental, good-faith violations of this Policy.
This statement:
Cafiyn reserves all legal rights regarding harmful, reckless, fraudulent, abusive, or unlawful activities.
Unless expressly announced otherwise:
Cafiyn may, at its sole discretion, acknowledge contributions or provide recognition.
Violations may result in:
Cafiyn reserves sole discretion regarding enforcement actions.
Cafiyn may suspend or terminate access immediately where necessary to:
Suspension or termination does not limit any other remedies available to Cafiyn.
Cafiyn may modify this Policy periodically to reflect:
Updated versions will be published with a revised effective date. Continued use of the Services following publication of an updated Policy constitutes acceptance of the revised Policy.
Security and vulnerability reports: infosec@cafiyn.com
General support: support@cafiyn.com
Questions regarding this Policy, security concerns, abuse reports, or vulnerability disclosures should be directed to the appropriate contact above.
Questions about this policy? Email infosec@cafiyn.com.
← All policies