Security program
Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), protects the platform with commercially reasonable safeguards: account scoping, role-based access, session controls, CSRF protection, password hashing, two-step verification, rate limiting on authentication, audit logging, and provider security controls. Safeguards are proportionate to the sensitivity of the data handled and are reviewed as the service evolves.
Client account security
Clients must keep credentials confidential, use strong unique passwords, restrict access to authorized users, and tell GCS promptly about suspected compromise or access that does not look right. GCS may reset credentials, end sessions, or require re-verification when risk is suspected.
Two-step verification
Two-step verification is available to client users and is required for administrator and operator access. Recovery codes must be stored securely and never shared.
Operator and admin security
Internal operator access is scoped, versioned per session, protected by two-step verification, and logged. Administrative actions on client accounts write audit entries.
Access controls and scoping
Workspaces are scoped by account and role. Client users see their own account's data; internal tools are separated from client surfaces. Suspected scoping failures must be reported immediately and must not be exploited or copied.
Audit logs
GCS records security-relevant events — authentication, activation, legal acceptance, lifecycle changes, administrative actions — with privacy-safe identifiers (salted hashes rather than raw IP or browser strings on acceptance records).
Provider credential handling
Provider credentials are stored as configuration secrets, never displayed back in full, never written into client-visible pages, and used only for the integration they belong to. Clients supplying their own provider credentials must keep them current and revoke them when ending the integration.
Incident response
GCS investigates suspected incidents, contains them, preserves evidence, and notifies affected clients and individuals where the law or the Data Processing Addendum requires. Incident reports go to [email protected] with timestamps and affected accounts.
Backups and recovery
Encrypted backups support recovery from failure. Backups cycle out on a fixed schedule; data removed from the live system leaves backups as those cycles complete.
Responsible disclosure
Security researchers should contact GCS before testing and must not access customer data, disrupt service, or disclose issues publicly before a coordinated review.
Limits
No system is perfectly secure. GCS commits to reasonable, honest safeguards and rapid response — not to absolute security.
Support / Contact
Questions about this security record may be sent to [email protected].