Report an incident
Send suspected security incidents to support@scalovus.com with “Security Incident” in the subject. Include the affected service, time, observed behavior and safe reproduction details. Do not include passwords, private keys, tokens, payment-card data, or trading credentials.
Response lifecycle
- Receive and triage: record the report, establish severity, preserve relevant evidence, and assign ownership.
- Contain: limit affected access, credentials, services, integrations, or deployments while preserving safe customer operations where possible.
- Investigate: establish scope, timeline, affected systems and data, root cause, and whether unauthorized access occurred.
- Eradicate and recover: remove the cause, rotate affected secrets, restore verified service, increase monitoring, and validate boundaries.
- Notify: inform affected customers, providers, insurers, acquiring partners, or authorities when required by law, contract, or material risk.
- Review: document corrective actions, owners, deadlines, and lessons learned; verify completion.
Severity and escalation
Events involving credentials, payment workflows, personal information, licensing authority, customer isolation, unauthorized administrative access, or material production interruption receive immediate escalation. Scalovus maintains decision records without publishing sensitive defensive details.
Customer action
If you suspect compromise, stop exposing the affected credential, preserve relevant timestamps, contact support, and follow broker or prop-firm emergency procedures. Continue monitoring and retain the ability to intervene directly in every trading account.
