Security & Responsible Disclosure

Last updated: August 5, 2026

Multipolar Defense, LLC ("we," "us," or "our") takes the security of our website, investor portal, marketplace, services configurator, and all related services (collectively, the "Services") seriously. This Security & Responsible Disclosure Policy describes our security practices and how you can report security vulnerabilities.

1. Our Security Practices

We implement appropriate technical and organizational measures to protect the Services and the information we process, including:

  • Encryption in Transit: All traffic to and from the Services is encrypted using TLS/HTTPS.
  • Authentication and Access Controls: The investor portal requires authentication, and access to sensitive information is role-based and restricted to authorized users.
  • Secure Infrastructure: Our hosting and database providers (Vercel and Supabase) maintain industry-standard security certifications and practices.
  • Monitoring and Logging: We monitor the Services for security threats and maintain logs to detect and respond to incidents.
  • Data Minimization: We collect only the information necessary to operate the Services.

2. Responsible Disclosure

We welcome reports of security vulnerabilities from the security research community. If you discover a vulnerability in the Services, we ask that you:

  • Report the vulnerability to us promptly at info@multipolardefense.com.
  • Provide sufficient detail to allow us to reproduce and understand the vulnerability.
  • Allow us a reasonable period of time to investigate and remediate the vulnerability before disclosing it publicly.
  • Act in good faith to avoid privacy violations, destruction of data, and interruption or degradation of the Services.
  • Not exploit the vulnerability beyond what is necessary to demonstrate the issue.

3. Out of Scope

The following activities are outside the scope of this policy and are not authorized:

  • Denial of service attacks.
  • Social engineering attacks against our employees, contractors, or users.
  • Physical attacks against our facilities or infrastructure.
  • Accessing, modifying, or exfiltrating data beyond what is necessary to demonstrate a vulnerability.
  • Testing third-party services or infrastructure not under our control.

4. Our Commitment

We will acknowledge receipt of vulnerability reports within a reasonable timeframe, investigate each report, and work to remediate confirmed vulnerabilities. We will not take legal action against researchers who act in good faith and in accordance with this policy.

5. Contact

To report a security vulnerability, please contact us at info@multipolardefense.com.

This Security & Responsible Disclosure Policy is provided for general informational purposes and does not constitute legal advice. Multipolar Defense, LLC recommends that you consult with qualified legal counsel regarding any questions you may have about this policy.