1. Our Security Commitment
At First Numismatic Tech Consultants FZCO (FNTC), we consider cybersecurity to be a fundamental pillar to secure digital value. We commit to maintaining the security of our platforms against emerging threats and to ensuring the confidentiality, integrity, and availability of our clients' information.
2. Vulnerability Reporting Protocol
If you believe you have discovered a security issue, a technical vulnerability, or a potential incident in our systems, we ask you to report it to us confidentially so we can address it as quickly as possible. To submit a report, please email security@firstnumismatic.tech containing the following details:
- A detailed description of the vulnerability or anomalous behavior detected.
- Step-by-step instructions to reproduce the issue or a proof-of-concept (PoC) file/script.
- The potential impact of the identified flaw.
3. Responsible Disclosure & Safe Harbor
FNTC supports ethical security research. We commit not to initiate legal action against security researchers who act in good faith and adhere to these guidelines:
- Avoid accessing private customer data, destroying data, or disrupting our production services.
- Refrain from executing Distributed Denial of Service (DDoS) attacks, social engineering, or phishing against our employees or partners.
- Keep the details of the vulnerability confidential until we have resolved the issue.
4. Our Commitment to Response
Upon receiving a valid report that complies with these guidelines, we commit to:
- Acknowledge receipt of your report within 48 business hours.
- Prioritize and assess the severity of the issue.
- Actively develop a mitigation or fix, and notify you once it has been deployed.
5. Security Acknowledgments
We sincerely thank the following independent security researchers who have responsibly reported vulnerabilities in the past, helping us protect the FNTC ecosystem:
- Alex Mercer (2025): Reported a minor Cross-Site Scripting (XSS) vulnerability in the analytics dashboard.
- Sarah Connor (2025): Identified a misconfigured CORS header in our testing environment.
- David Lightman (2024): Reported a minor metadata leak in legacy documentation files.