Updated 15 August 2026

Security Policy

Security expectations for accounts, payments, content access, and platform operation.

Signing is unavailable while this document remains a draft. It must have a recorded professional review, approval date, and final version before it can be accepted.

Security controls

Production enforces HTTPS, secure headers, environment secret management, Stripe webhook signature verification, least-privilege cloud roles, protected member routes, versioned policy acceptance, private non-cacheable downloads, personalised trace markers, proportionate rate limits, account monitoring, dependency updates, logging, and backup processes.

Payment secrets must remain server-side only. Stripe publishable keys may be exposed to the browser, but secret keys and webhook secrets must never be committed to source control.

Reporting issues

Security concerns must be sent to security@cloudforgeacademy.co.uk. Legal notices must be sent to legal@cloudforgeacademy.co.uk.

High-impact vulnerability and data-exposure reports are triaged within one UK business day. Lower-risk security questions are reviewed within two UK business days.

Responsible disclosure reports should include affected URLs, approximate times, safe reproduction notes, likely impact, and contact details without accessing other users' data or including secrets.

Launch note

This page is a production-readiness template. It should be reviewed against the final business entity, domain, payment setup, processors, jurisdictions, and customer support process before full commercial launch.