Tool-O
Security Policy
Tool-O is committed to maintaining the security, integrity and availability of the Platform and protecting the information entrusted to it by Users.
1. INTRODUCTION
1.1 Purpose
Tool-O is committed to maintaining the security, integrity and availability of the Platform and protecting the information entrusted to it by Users.
This Security Policy outlines Tool-O's approach to safeguarding its systems, data and services against unauthorised access, misuse, cyber threats and other security risks.
1.2 Scope
This Policy applies to:
- the Tool-O Platform;
- User Accounts;
- Platform infrastructure;
- employees;
- contractors;
- service providers where applicable;
- Users interacting with the Platform.
1.3 Objectives
Tool-O seeks to:
- protect User information;
- maintain Platform availability;
- safeguard Platform integrity;
- reduce security risks;
- respond appropriately to security incidents;
- continually improve security practices.
1.4 Shared Responsibility
Security is a shared responsibility.
Tool-O implements reasonable technical and organisational measures to protect the Platform, while Users are responsible for protecting their own Account credentials, devices and personal information.
1.5 Relationship with Other Policies
This Security Policy should be read together with the:
- Terms of Use;
- Privacy Policy;
- Acceptable Use Policy;
- Community Guidelines;
- all other Platform policies.
1.6 Continuous Improvement
Cybersecurity threats continue to evolve.
Tool-O is committed to regularly reviewing and improving its security practices, technologies and procedures as the Platform grows.
2. SECURITY MEASURES
2.1 Security Controls
Tool-O seeks to implement reasonable administrative, technical and organisational measures designed to protect the Platform and User information.
2.2 Account Security
Users are responsible for maintaining the security of their Accounts, including:
- keeping passwords confidential;
- using strong passwords;
- protecting authentication credentials;
- logging out from shared devices where appropriate;
- promptly notifying Tool-O of suspected unauthorised access.
2.3 Authentication
Tool-O may implement authentication measures including:
- password protection;
- multi-factor authentication where available;
- session management;
- account verification;
- other appropriate security controls.
2.4 Data Protection
Tool-O seeks to protect User information through reasonable security measures appropriate to the nature of the information being stored or processed.
2.5 System Monitoring
Tool-O may monitor Platform systems to:
- detect security threats;
- identify suspicious activity;
- investigate security incidents;
- maintain Platform integrity;
- improve security controls.
2.6 Third-Party Providers
Tool-O may engage reputable third-party providers for services including:
- payment processing;
- cloud hosting;
- communications;
- authentication;
- analytics;
- infrastructure.
While Tool-O seeks to engage providers that maintain appropriate security standards, it cannot guarantee the security of third-party systems beyond its control.
2.7 Security Updates
Tool-O may periodically update, modify or replace Platform software, infrastructure and security controls to address emerging risks and improve security.
2.8 User Responsibilities
Users should:
- keep devices reasonably secure;
- maintain current software updates;
- use trusted internet connections where appropriate;
- avoid sharing Account credentials;
- report suspected security issues promptly.
2.9 Prohibited Activities
Users must not attempt to:
- gain unauthorised access to the Platform;
- bypass security controls;
- interfere with Platform operations;
- introduce malicious software;
- exploit security vulnerabilities;
- disrupt other Users.
Such conduct may result in immediate enforcement action.
2.10 No Absolute Security
Although Tool-O implements reasonable security measures, no internet service, computer system or electronic transmission can be guaranteed to be completely secure.
Users acknowledge that security risks cannot be entirely eliminated.
3. SECURITY INCIDENTS
3.1 Security Incident Response
Tool-O seeks to respond promptly and appropriately to security incidents affecting the Platform, taking into account the nature and severity of the incident.
3.2 Examples of Security Incidents
Security incidents may include, without limitation:
- unauthorised access;
- attempted hacking;
- malware;
- phishing attacks;
- credential compromise;
- denial of service attacks;
- data breaches;
- fraudulent activity;
- system misuse.
3.3 Detection
Tool-O may use reasonable monitoring, logging and security tools to assist in identifying potential security incidents.
3.4 Investigation
Where a security incident is identified or reasonably suspected, Tool-O may:
- investigate the incident;
- preserve relevant evidence;
- temporarily restrict Platform functionality;
- suspend affected Accounts;
- engage security specialists;
- notify relevant service providers where appropriate.
3.5 Containment
Tool-O may take reasonable measures to contain or minimise the impact of a security incident, including temporarily restricting access to affected systems where necessary.
3.6 User Cooperation
Users agree to reasonably cooperate with Tool-O in responding to security incidents, including by:
- changing passwords;
- verifying Account ownership;
- providing relevant information;
- following reasonable security instructions.
3.7 Notifications
Where required by applicable law, Tool-O may notify affected Users and relevant authorities of certain security incidents.
The timing and content of any notification will depend on the circumstances of the incident and applicable legal requirements.
3.8 Recovery
Following a security incident, Tool-O may take reasonable steps to restore Platform functionality, improve security controls and reduce the likelihood of similar incidents occurring in the future.
3.9 No Guarantee
Tool-O cannot guarantee that security incidents will never occur despite implementing reasonable security measures.
3.10 Continuous Improvement
Lessons learned from security incidents may be used to strengthen Tool-O's security practices, policies and technical safeguards.
4. REVIEW AND CONTINUOUS IMPROVEMENT
4.1 Ongoing Review
Tool-O may periodically review this Security Policy to ensure it remains appropriate for the Platform's operations, emerging threats and evolving technology.
4.2 Security Assessments
Tool-O may conduct reasonable security assessments including:
- vulnerability assessments;
- penetration testing;
- configuration reviews;
- infrastructure reviews;
- software updates;
- risk assessments.
4.3 Continuous Improvement
Tool-O is committed to continually improving its security framework through:
- enhanced security controls;
- updated procedures;
- improved monitoring;
- staff awareness;
- technological improvements;
- lessons learned from security incidents.
4.4 Compliance
Tool-O seeks to comply with applicable laws, regulations and industry standards relating to cybersecurity, information security and data protection.
Nothing in this Policy limits any legal rights or obligations that cannot lawfully be excluded.
4.5 Third-Party Security
Where third-party providers are engaged, Tool-O may reasonably assess their suitability and security practices before or during engagement.
However, Tool-O cannot guarantee the ongoing security of systems operated by independent third parties.
4.6 Responsible Disclosure
Individuals who reasonably believe they have identified a genuine security vulnerability affecting the Platform are encouraged to report it responsibly to Tool-O.
Users must not exploit, disclose publicly or misuse vulnerabilities before Tool-O has had a reasonable opportunity to investigate and respond.
4.7 Policy Updates
Tool-O may amend this Security Policy from time to time.
The most current version published on the Platform replaces all previous versions.
4.8 Relationship with Other Policies
This Security Policy should be read together with the:
- Terms of Use;
- Privacy Policy;
- Acceptable Use Policy;
- Community Guidelines;
- all other Platform policies.
Where there is any inconsistency, the Terms of Use prevail to the extent permitted by applicable law.
4.9 Contact
Users who become aware of a suspected security issue affecting the Platform are encouraged to notify Tool-O using the contact details published on the Platform as soon as reasonably practicable.
4.10 Final Statement
Security is fundamental to maintaining trust within the Tool-O marketplace.
Tool-O remains committed to protecting its Platform, supporting Users and continually strengthening its security practices as technology and cybersecurity risks evolve.
END OF SECURITY POLICY
