Moltrensok
Moltrensok design principles
global access — any time zone
structured learning paths
interactive lessons

Security Policy

Last updated: March 24, 2026

Moltrensok is committed to protecting the security of its platform, services, and the data entrusted to us by our users. This Security Policy describes the technical and organizational measures we implement to safeguard information processed through moltrensok.com.


1. Scope

This policy applies to all systems, infrastructure, applications, and processes operated by Moltrensok that store, transmit, or process user data in connection with the delivery of our online education services. It covers internal operations as well as interactions with third-party service providers.


2. Data Protection Principles

We apply the following core principles when handling user data:


3. Infrastructure Security

3.1 Hosting and Network

Our platform is hosted on infrastructure provided by reputable cloud service providers that maintain industry-standard physical and environmental security controls. Network access is restricted through firewalls, access control lists, and segmentation to limit exposure of internal systems.

3.2 Encryption in Transit

All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce current protocol versions and strong cipher suites. Unencrypted connections are not accepted for any user-facing endpoint.

3.3 Encryption at Rest

Sensitive data stored on our systems is encrypted at rest using industry-accepted encryption standards. Encryption keys are managed through dedicated key management practices and are rotated on a defined schedule.

3.4 Data Backups

Regular automated backups are performed for critical data. Backups are encrypted and stored in geographically separated locations. Restoration procedures are tested periodically to verify reliability.


4. Application Security

4.1 Secure Development Practices

Our development team follows secure coding guidelines throughout the software development lifecycle. Code changes undergo review before deployment. Security considerations are addressed during design, development, and testing phases.

4.2 Vulnerability Management

We conduct periodic vulnerability assessments of our systems and applications. Identified vulnerabilities are prioritized and remediated according to their severity. Critical issues are addressed on an expedited basis.

4.3 Dependency Management

Third-party libraries and software components used in our platform are monitored for known vulnerabilities. Updates and patches are applied in a timely manner to maintain a secure software supply chain.

4.4 Authentication and Access Controls

User accounts are protected by authentication mechanisms including password requirements and support for multi-factor authentication where available. Administrative access to production systems is restricted to authorized personnel and requires strong authentication. Privileged access is logged and reviewed.

4.5 Session Management

User sessions are managed securely. Session tokens are generated with sufficient entropy, transmitted only over encrypted connections, and invalidated upon logout or after a defined period of inactivity.


5. Organizational Security

5.1 Access Control Policy

Access to systems and data is granted on a least-privilege basis. Access rights are reviewed periodically and revoked promptly when no longer required, including upon termination of employment or change of role.

5.2 Employee Responsibilities

All personnel with access to user data or internal systems are required to understand and follow our security policies. Employees handling sensitive information receive appropriate guidance on their obligations and the risks associated with misuse or negligence.

5.3 Third-Party Providers

We evaluate the security practices of third-party service providers before engagement. Providers who process user data on our behalf are required to maintain appropriate security standards. We review these relationships periodically.

5.4 Physical Security

Access to physical locations where data processing equipment is operated is controlled and limited to authorized individuals. Our cloud infrastructure providers maintain their own physical security controls in accordance with recognized standards.


6. Monitoring and Logging

We maintain logs of access and activity across critical systems. Logs are retained for a defined period and are reviewed to detect anomalous behavior, unauthorized access attempts, or potential security incidents. Monitoring tools are in place to generate alerts for events that may indicate a security concern.


7. Incident Response

7.1 Incident Identification

We maintain procedures for identifying and classifying potential security incidents. Anomalies detected through monitoring, user reports, or other means are investigated promptly.

7.2 Containment and Remediation

Upon confirmation of a security incident, we take immediate steps to contain the impact, preserve evidence, and remediate the root cause. Affected systems are assessed and restored to a secure state.

7.3 Notification

In the event of a security incident that affects user data, we will notify impacted users in a timely manner consistent with our legal obligations. Notifications will describe the nature of the incident and the steps being taken in response.

7.4 Post-Incident Review

Following any significant security incident, we conduct a review to identify lessons learned and implement improvements to prevent recurrence.


8. Security Testing

We perform periodic security testing of our platform, including vulnerability scans and application-level assessments. Where appropriate, we engage qualified external parties to conduct independent security evaluations. Findings are reviewed and addressed according to their risk level.


9. Responsible Disclosure

We welcome reports of potential security vulnerabilities from security researchers and users. If you believe you have identified a security issue affecting our platform, please contact us at support@moltrensok.com before disclosing it publicly. We commit to acknowledging reports promptly and working in good faith to investigate and address confirmed issues.

Please include in your report:

We ask that researchers refrain from accessing, modifying, or deleting data belonging to other users, disrupting service availability, or publicly disclosing details before we have had a reasonable opportunity to respond.


10. Data Retention and Deletion

User data is retained only for as long as necessary to provide our services or as required by applicable obligations. When data is no longer needed, it is securely deleted or anonymized. Users may request deletion of their personal data in accordance with our Privacy Policy.


11. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the date at the top of this page. Continued use of our services after changes are posted constitutes acceptance of the revised policy.


12. Contact

If you have questions or concerns about this Security Policy or the security of our platform, please contact us: