Remsee Security Policy

Version: v1.0
Effective date: 29 June 2026
Company: Numtrend Co., Ltd.

1. Purpose

This Security Policy describes Remsee's security commitments, user responsibilities, vulnerability reporting process, and incident communication framework.

2. Security Program

Remsee aims to maintain administrative, technical, and organizational safeguards appropriate to the nature of the Service, including:

  1. Secure authentication.
  2. Role-based access controls.
  3. Encryption in transit and where appropriate at rest.
  4. Logging and monitoring.
  5. Vulnerability management.
  6. Secure development practices.
  7. Access reviews.
  8. Backup and recovery processes.
  9. Vendor security review.
  10. Incident response procedures.

3. User Responsibilities

Users must:

  1. Keep credentials secure.
  2. Use strong passwords and device protections.
  3. Promptly report suspicious activity.
  4. Not share Accounts.
  5. Not attempt unauthorized access or security testing.

4. Vulnerability Reporting

Report suspected vulnerabilities to security@numtrend.com with:

  1. Description of the issue.
  2. Affected endpoint, feature, or system.
  3. Reproduction steps.
  4. Potential impact.
  5. Your contact information.

5. Security Research Rules

Researchers must not:

  1. Access, modify, delete, copy, or exfiltrate data.
  2. Disrupt the Service.
  3. Use social engineering, phishing, spam, physical attacks, or denial-of-service testing.
  4. Test third-party systems without permission.
  5. Publicly disclose vulnerabilities before coordinated resolution.

6. Safe Harbor Placeholder

Remsee may provide safe harbor for good-faith research that complies with this policy. Scope, eligibility, bounty status, disclosure timelines, and legal safe harbor language require counsel and security approval.

7. Incident Response

  1. Remsee will investigate suspected security incidents.
  2. Where required by law, Remsee will notify affected Users, regulators, partners, or other parties.
  3. Notifications may include incident type, affected data, mitigation steps, and recommended user actions where appropriate.

8. Data Protection

Security controls supporting Personal Data protection are described in the Privacy Policy and Data Processing Agreement.

9. No Warranty

No system is completely secure. This policy does not create a guarantee that incidents will not occur.

10. Contact

Security: security@numtrend.com
Privacy: privacy@numtrend.com

11. Governing Law

This Security Policy is subject to the laws of the Kingdom of Thailand, with the courts of Bangkok having jurisdiction, unless mandatory privacy, cybersecurity, or consumer law provides otherwise.

12. Change History

| Version | Date | Owner | Summary | | --- | --- | --- | --- | | v1.0 | 29 June 2026 | NUMTREND Co., Ltd. | Initial Security Policy draft. | | v1.0 | 29 June 2026 | NUMTREND Co., Ltd. | Reviewed and approved by NUMTREND — ready for use. |