Security Policy
Last updated: March 24, 2026
Moltrensok is committed to protecting the security of its platform, services, and the data entrusted to us by our users. This Security Policy describes the technical and organizational measures we implement to safeguard information processed through moltrensok.com.
1. Scope
This policy applies to all systems, infrastructure, applications, and processes operated by Moltrensok that store, transmit, or process user data in connection with the delivery of our online education services. It covers internal operations as well as interactions with third-party service providers.
2. Data Protection Principles
We apply the following core principles when handling user data:
- Minimum necessary access: Data is accessible only to personnel and systems that require it to perform a specific function.
- Purpose limitation: Data collected for one purpose is not repurposed without appropriate basis.
- Integrity and confidentiality: Appropriate measures are in place to prevent unauthorized access, alteration, disclosure, or destruction of data.
- Accountability: We maintain records of data processing activities and security controls to demonstrate compliance.
3. Infrastructure Security
3.1 Hosting and Network
Our platform is hosted on infrastructure provided by reputable cloud service providers that maintain industry-standard physical and environmental security controls. Network access is restricted through firewalls, access control lists, and segmentation to limit exposure of internal systems.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce current protocol versions and strong cipher suites. Unencrypted connections are not accepted for any user-facing endpoint.
3.3 Encryption at Rest
Sensitive data stored on our systems is encrypted at rest using industry-accepted encryption standards. Encryption keys are managed through dedicated key management practices and are rotated on a defined schedule.
3.4 Data Backups
Regular automated backups are performed for critical data. Backups are encrypted and stored in geographically separated locations. Restoration procedures are tested periodically to verify reliability.
4. Application Security
4.1 Secure Development Practices
Our development team follows secure coding guidelines throughout the software development lifecycle. Code changes undergo review before deployment. Security considerations are addressed during design, development, and testing phases.
4.2 Vulnerability Management
We conduct periodic vulnerability assessments of our systems and applications. Identified vulnerabilities are prioritized and remediated according to their severity. Critical issues are addressed on an expedited basis.
4.3 Dependency Management
Third-party libraries and software components used in our platform are monitored for known vulnerabilities. Updates and patches are applied in a timely manner to maintain a secure software supply chain.
4.4 Authentication and Access Controls
User accounts are protected by authentication mechanisms including password requirements and support for multi-factor authentication where available. Administrative access to production systems is restricted to authorized personnel and requires strong authentication. Privileged access is logged and reviewed.
4.5 Session Management
User sessions are managed securely. Session tokens are generated with sufficient entropy, transmitted only over encrypted connections, and invalidated upon logout or after a defined period of inactivity.
5. Organizational Security
5.1 Access Control Policy
Access to systems and data is granted on a least-privilege basis. Access rights are reviewed periodically and revoked promptly when no longer required, including upon termination of employment or change of role.
5.2 Employee Responsibilities
All personnel with access to user data or internal systems are required to understand and follow our security policies. Employees handling sensitive information receive appropriate guidance on their obligations and the risks associated with misuse or negligence.
5.3 Third-Party Providers
We evaluate the security practices of third-party service providers before engagement. Providers who process user data on our behalf are required to maintain appropriate security standards. We review these relationships periodically.
5.4 Physical Security
Access to physical locations where data processing equipment is operated is controlled and limited to authorized individuals. Our cloud infrastructure providers maintain their own physical security controls in accordance with recognized standards.
6. Monitoring and Logging
We maintain logs of access and activity across critical systems. Logs are retained for a defined period and are reviewed to detect anomalous behavior, unauthorized access attempts, or potential security incidents. Monitoring tools are in place to generate alerts for events that may indicate a security concern.
7. Incident Response
7.1 Incident Identification
We maintain procedures for identifying and classifying potential security incidents. Anomalies detected through monitoring, user reports, or other means are investigated promptly.
7.2 Containment and Remediation
Upon confirmation of a security incident, we take immediate steps to contain the impact, preserve evidence, and remediate the root cause. Affected systems are assessed and restored to a secure state.
7.3 Notification
In the event of a security incident that affects user data, we will notify impacted users in a timely manner consistent with our legal obligations. Notifications will describe the nature of the incident and the steps being taken in response.
7.4 Post-Incident Review
Following any significant security incident, we conduct a review to identify lessons learned and implement improvements to prevent recurrence.
8. Security Testing
We perform periodic security testing of our platform, including vulnerability scans and application-level assessments. Where appropriate, we engage qualified external parties to conduct independent security evaluations. Findings are reviewed and addressed according to their risk level.
9. Responsible Disclosure
We welcome reports of potential security vulnerabilities from security researchers and users. If you believe you have identified a security issue affecting our platform, please contact us at support@moltrensok.com before disclosing it publicly. We commit to acknowledging reports promptly and working in good faith to investigate and address confirmed issues.
Please include in your report:
- A clear description of the potential vulnerability
- Steps to reproduce the issue
- Any relevant technical details such as affected URLs, parameters, or system components
- Your assessment of the potential impact
We ask that researchers refrain from accessing, modifying, or deleting data belonging to other users, disrupting service availability, or publicly disclosing details before we have had a reasonable opportunity to respond.
10. Data Retention and Deletion
User data is retained only for as long as necessary to provide our services or as required by applicable obligations. When data is no longer needed, it is securely deleted or anonymized. Users may request deletion of their personal data in accordance with our Privacy Policy.
11. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the date at the top of this page. Continued use of our services after changes are posted constitutes acceptance of the revised policy.
12. Contact
If you have questions or concerns about this Security Policy or the security of our platform, please contact us:
- Email: support@moltrensok.com
- Phone: +380432670107
- Address: Naukova St, 64А, Lviv, Lviv Oblast, Ukraine, 79060