Security Policy
Last updated: 25 January 2026
Vegasoffer2026 ("we", "us", "our") operates the platform available at vegasoffer2026.com. We are committed to protecting the security of our systems and the data entrusted to us by our users. This Security Policy describes the technical and organisational measures we apply to safeguard our platform, infrastructure, and user information.
1. Scope
This policy applies to all systems, services, and data assets operated by Vegasoffer2026, including our web application, backend infrastructure, communication channels, and any third-party integrations used to deliver our educational platform.
2. Data Protection and Encryption
2.1 Data in Transit
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS 1.2 or higher). We enforce HTTPS across all pages and services. Unencrypted HTTP connections are automatically redirected to secure HTTPS endpoints.
2.2 Data at Rest
Sensitive data stored on our servers is encrypted at rest using industry-standard encryption algorithms. Database backups are also encrypted and stored in access-controlled environments.
2.3 Password Storage
User passwords are never stored in plain text. We apply strong one-way hashing algorithms with per-record salting to ensure that passwords cannot be recovered even in the event of unauthorised database access.
3. Access Control
3.1 Principle of Least Privilege
Access to production systems, databases, and sensitive configuration is granted on a need-to-know basis. Each team member is assigned only the minimum permissions required to perform their role.
3.2 Authentication Requirements
Administrative access to internal systems requires multi-factor authentication (MFA). Shared credentials are prohibited. All privileged sessions are logged and subject to periodic review.
3.3 User Account Security
Users are encouraged to choose strong, unique passwords for their accounts. Our platform enforces minimum password complexity requirements and provides mechanisms for secure account recovery. Suspicious login activity may trigger additional verification steps.
4. Infrastructure Security
4.1 Hosting and Network
Our platform is hosted on reputable cloud infrastructure providers that maintain their own security certifications and compliance programmes. Network access is controlled through firewalls and security groups that restrict traffic to authorised sources and services only.
4.2 Patch Management
We maintain a patch management process to ensure that operating systems, application dependencies, and third-party libraries are kept up to date. Critical security patches are applied promptly upon release.
4.3 Vulnerability Management
We conduct periodic vulnerability assessments of our platform and infrastructure. Identified vulnerabilities are triaged by severity and remediated according to defined timelines. We also review security advisories relevant to our technology stack on an ongoing basis.
5. Application Security
5.1 Secure Development Practices
Our development process incorporates security considerations at each stage, including design review, code review, and testing. We follow established secure coding guidelines to mitigate common application vulnerabilities such as those described in the OWASP Top Ten.
5.2 Input Validation and Output Encoding
All user-supplied input is validated and sanitised before processing. Output is appropriately encoded to prevent injection attacks, including SQL injection and cross-site scripting (XSS).
5.3 Session Management
User sessions are managed using secure, randomly generated tokens. Sessions are invalidated upon logout and expire after a period of inactivity. Session tokens are transmitted only over encrypted connections.
6. Monitoring and Logging
We maintain logging of significant system events, including authentication attempts, administrative actions, and application errors. Logs are retained for a defined period and reviewed periodically or in response to security events. Automated alerting is in place to notify our team of anomalous activity.
7. Incident Response
We maintain an incident response procedure to address security events in a structured and timely manner. In the event of a confirmed security incident affecting user data, we will notify affected users and relevant parties in accordance with our obligations and as promptly as the circumstances allow. Notifications will be sent to the email address associated with each affected account.
To report a suspected security incident or vulnerability, please contact us at contact@vegasoffer2026.com.
8. Third-Party Services
We use third-party service providers to support the operation of our platform, including payment processors, analytics tools, and communication services. We evaluate third parties for their security practices before engagement and require that they handle data in a manner consistent with our standards. We do not sell or share user data with third parties for advertising purposes.
9. Physical Security
Our platform operates entirely on cloud infrastructure. We do not operate physical data centres. Our cloud providers maintain physical security controls including restricted facility access, environmental controls, and surveillance systems.
10. Backup and Recovery
We perform regular automated backups of platform data. Backups are encrypted and stored in geographically separate locations where feasible. We periodically test our recovery procedures to verify that data can be restored within acceptable timeframes in the event of system failure or data loss.
11. Employee Security
Team members with access to user data or production systems are informed of their security responsibilities. Access is revoked promptly upon the conclusion of employment or engagement. We apply background screening processes appropriate to the level of access granted.
12. Responsible Disclosure
We welcome responsible disclosure of security vulnerabilities from security researchers and users. If you believe you have identified a security issue affecting our platform, please report it to us at contact@vegasoffer2026.com before disclosing it publicly. We will acknowledge your report, investigate the issue, and work to resolve it in a timely manner. We ask that you do not access, modify, or disclose user data while conducting research.
13. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or regulatory environment. The date at the top of this page indicates when the policy was last revised. We encourage you to review this policy periodically.
14. Contact
If you have questions about this Security Policy or our security practices, you may contact us by any of the following means:
| Method | Details |
|---|---|
| contact@vegasoffer2026.com | |
| Phone | +61 2 9805 0887 |
| Post | 35 Mulgrave St, Bundaberg West QLD 4670, Australia |