All documents

Security and Responsible Vulnerability Disclosure Policy

Final version V1 · August 7, 2026 · CG INVESTORHOOD ENTERPRISE S.R.L.

Final version V1 · August 7, 2026 · CG INVESTORHOOD ENTERPRISE S.R.L.

1. Our Commitment

Investorhood aims to protect accounts, data, and infrastructure through technical and organizational measures proportionate to the risks.

No system is completely immune.

2. Reporting a Vulnerability

Send your report to:

security@investorhood.com
Subject: "SECURITY – CONFIDENTIAL"

Include, if possible:

  • the affected component;
  • the reproduction steps;
  • the impact;
  • redacted screenshots/logs;
  • the app version;
  • your contact details.

Do not send personal data that is not necessary.

3. Activities Permitted Within the Limits of Good Faith

Research must:

  • use only your own accounts/data or explicit permissions;
  • minimize the impact;
  • stop after the issue is confirmed;
  • not retain accidentally accessed data;
  • comply with the law.

4. Prohibited Activities

Do not perform:

  • DoS or testing that degrades the service;
  • access to other users' data;
  • data exfiltration/modification/deletion;
  • phishing or social engineering;
  • malware;
  • spam;
  • blackmail based on disclosing the vulnerability.

5. Investorhood's Response

We aim to confirm receipt, assess the severity, and remediate according to the risk and complexity.

The communicated timeframes are objectives, not contractual guarantees.

6. No Automatic Reward Program

Submitting a report does not automatically create a right to a reward.

7. Protection of Good-Faith Research

Good faith and compliance with this Policy will be taken into consideration, without this Policy authorizing any violation of the law.

8. Account Security for Users

  • use a unique password;
  • protect the associated email address;
  • do not share your password or codes;
  • keep the app and your system up to date;
  • report suspicious activity.

V1 does not offer biometric authentication or public 2FA.

9. Incidents and Phishing

For a compromised account or a suspicious message, write to security@investorhood.com and immediately change your Investorhood password and the password of the associated email account.

Investorhood does not ask for your password, full card details, private key, or seed phrase.

10. Contact

security@investorhood.com