Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), protects the platform with commercially reasonable safeguards: account scoping, role-based access, session controls, CSRF protection, password hashing, two-step verification, rate limiting on authentication, audit logging, and provider security controls. Safeguards are proportionate to the sensitivity of the data handled and are reviewed as the service evolves.
Clients must keep credentials confidential, use strong unique passwords, restrict access to authorized users, and tell GCS promptly about suspected compromise or access that does not look right. GCS may reset credentials, end sessions, or require re-verification when risk is suspected.
Two-step verification is available to client users and is required for administrator and operator access. Recovery codes must be stored securely and never shared.
Internal operator access is scoped, versioned per session, protected by two-step verification, and logged. Administrative actions on client accounts write audit entries.
Workspaces are scoped by account and role. Client users see their own account's data; internal tools are separated from client surfaces. Suspected scoping failures must be reported immediately and must not be exploited or copied.
GCS records security-relevant events — authentication, activation, legal acceptance, lifecycle changes, administrative actions — with privacy-safe identifiers (salted hashes rather than raw IP or browser strings on acceptance records).
Provider credentials are stored as configuration secrets, never displayed back in full, never written into client-visible pages, and used only for the integration they belong to. Clients supplying their own provider credentials must keep them current and revoke them when ending the integration.
GCS investigates suspected incidents, contains them, preserves evidence, and notifies affected clients and individuals where the law or the Data Processing Addendum requires. Incident reports go to [email protected] with timestamps and affected accounts.
Encrypted backups support recovery from failure. Backups cycle out on a fixed schedule; data removed from the live system leaves backups as those cycles complete.
Security researchers should contact GCS before testing and must not access customer data, disrupt service, or disclose issues publicly before a coordinated review.
No system is perfectly secure. GCS commits to reasonable, honest safeguards and rapid response — not to absolute security.
Questions about this security record may be sent to [email protected].