CATALYST ALPHA GROUP/SECURITYINSTITUTIONAL NOTICE

RESPONSIBLE SECURITY DISCLOSURE

Report carefully.
Reduce risk.

How to report a suspected security issue affecting the Catalyst Alpha Group Holdings public website responsibly.

01

Report a suspected issue

If you believe you have identified a security issue affecting the Catalyst Alpha Group Holdings public website, report it to the published website-security contact with a concise description of the issue, the affected URL or component, and the steps needed to reproduce it.

Please include only the evidence needed to understand the issue. Do not send passwords, authentication secrets, identity documents or unrelated personal information in an initial report.

02

Scope

This disclosure channel covers the public website served from catalystalphagroup.com and the production assets delivered with it.

Group company websites, email providers, hosting platforms and other external services reached from this site are separately controlled and should be reported through the security channels published by their respective operators.

03

Responsible testing

Avoid actions that could disrupt service, degrade availability, destroy or alter data, access information that is not necessary to demonstrate the issue, or affect other people. Use the minimum interaction required to validate a suspected weakness.

This page is a reporting policy, not authorization to bypass access controls, perform intrusive testing, violate applicable law, or disregard the terms of third-party systems.

04

Report handling

Security reports are reviewed through the official enquiries channel. Acknowledgement, investigation and remediation timing will depend on severity, reproducibility, affected systems and the availability of sufficient technical detail.

No public bug-bounty payment, reward or safe-harbor program should be inferred unless it is separately announced in writing through an official Catalyst Alpha Group Holdings disclosure.

05

Coordinated disclosure

Please allow a reasonable opportunity to investigate and address a validated issue before publishing technical details that could increase risk to the website or its visitors.

If coordinated public disclosure is appropriate, timing and attribution can be discussed through the security contact after the issue has been assessed.

WEBSITE SECURITY

Send the minimum technical detail needed to reproduce the issue.

[email protected]