সর্বশেষ আপডেট: ২৬ জুন, ২০২৬
সংক্ষিপ্ত বিবরণ
নিরাপত্তা SRS Cortex-এর কেন্দ্রে। পাবলিক মার্কেটিং পেজ ও authenticated workspace পৃথক, credentials/OAuth সুরক্ষা ও production anomaly মনিটরিং।
এই পেজ আমাদের approach সংক্ষেপে। ডেটা handling-এর জন্য Privacy Policy ও Transparency Report দেখুন।
Threats ও product capabilities বদলালে controls ক্রমাগত উন্নত করি।
অ্যাকাউন্ট নিরাপত্তা
পাসওয়ার্ড industry-standard hashing-এ সংরক্ষিত। সেশন secure HTTP-only cookies, expiration ও rotation সহ।
Role-based access দল সদস্যদের view/edit/publish সীমিত করে। Client review links scoped access দেয় full credentials ছাড়াই।
শক্তিশালী unique পাসওয়ার্ড, admin role সীমিত রাখা ও সদস্য চলে গেলে access প্রত্যাহারের পরামর্শ।
ডেটা সুরক্ষা
Transit-এ TLS encryption। Rest-এ EU cloud infrastructure-তে encrypted।
OAuth tokens ও API credentials encrypted, শুধু authorized backend access — client-side/public-এ expose হয় না।
Backup encrypted ও regular test। Production data access legitimate operational need-এ সীমিত।
ইনফ্রাস্ট্রাকচার
Cortex hardened cloud infrastructure — network segmentation, firewalls, automated security patching।
Monitoring, error tracking, alerting — outages, abuse, suspicious activity detect।
Service availability ও planned maintenance Status পেজে প্রকাশিত।
ইন্টিগ্রেশন
সোশ্যাল/মেসেজিং চ্যানেল platform-specific authorization দাবি। Cortex শুধু scheduling, publishing, analytics permissions চায়।
Third-party platforms API পরিবর্তন/token revoke করতে পারে। re-authorization লাগলে notify করি।
Payment certified providers; card data Cortex servers-এ store হয় না।
দুর্বলতা রিপোর্ট
SRS Cortex-এ security vulnerability পেলে Report a problem বা support form-এ reproduce steps সহ responsibly report করুন।
Investigate/remediate-এ reasonable time না পাওয়া পর্যন্ত publicly disclose করবেন না।
Valid reports promptly acknowledge করি ও researchers-এর সাথে good faith-এ কাজ করি।
নিরাপত্তা যোগাযোগ
Security প্রশ্ন বা incident follow-up: support form।
Data breach notification-এ প্রযোজ্য আইন অনুযায়ী affected users-কে contact করি।