Trust & security
Security & Responsible Disclosure
CHAMP Solutions applies risk-based safeguards to protect business information and welcomes good-faith reports that help us address suspected vulnerabilities responsibly.
Effective date: 26 August 2026
1. Security principles
- Risk-based governance, defined ownership, least privilege, separation of duties, and appropriate personnel confidentiality obligations.
- Secure transmission, controlled access, logging, monitoring, vulnerability management, backup, recovery, and incident-response processes proportionate to the service.
- Supplier and partner assessment where third parties process confidential, personal, or service data.
- Data minimisation, retention controls, secure disposal, and customer-specific safeguards established through contracts and implementation design.
2. Customer responsibilities
Customers and website users must protect devices, credentials, downloaded questionnaires, printed copies, and authorised-contact lists; promptly remove access for departing personnel; provide accurate incident contacts; and follow agreed security procedures. Do not send passwords, private keys, or unnecessary sensitive data through public email or website forms.
3. Reporting a suspected vulnerability
Email info@champsolutionz.com with the subject “Security report”. Include the affected URL or service, a clear description, reproduction steps that avoid further harm, date and time observed, potential impact, and a safe way to contact you. Do not include personal data or secrets beyond what is essential to understand the issue.
4. Good-faith reporting guidelines
- Stop testing and report promptly after confirming a potential issue.
- Avoid accessing, changing, downloading, retaining, or disclosing data that is not your own.
- Do not disrupt services, degrade availability, send spam, use malware, phish, socially engineer, test physical security, or target employees or third parties.
- Do not publicly disclose a suspected issue before CHAMP has had reasonable time to investigate and remediate.
- Comply with law and any contract or written scope that applies. If uncertain, request written permission before testing.
5. Our response
We aim to acknowledge credible reports, assess severity, request clarification where needed, and coordinate remediation and disclosure based on risk. Response times vary with complexity and service ownership. CHAMP does not promise payment or legal immunity, but will consider good-faith conduct and responsible reporting when evaluating a report.
6. Security incidents involving personal data
CHAMP maintains processes to assess and respond to suspected incidents. Where applicable law or contract requires notification to customers, individuals, regulators, or partners, CHAMP will make notifications through appropriate channels based on the facts and risk.
