Security & Breach Response Policy
Last Updated: September 7, 2026
This Security & Breach Response Policy (“Policy”) explains how Cry-Fi (“Cry-Fi”, “Platform”, “we”, “our”, or “us”) approaches Platform security, security incidents, and personal-data breach response.
Cry-Fi uses reasonable technical and organizational measures designed to protect the Platform and information processed through it. However, no internet-based service, system, or method of electronic transmission can guarantee absolute security.
1. Purpose
This Policy outlines Cry-Fi’s general approach to:
Platform security
Account protection
Security incident response
Personal-data breach response
User security responsibilities
Vulnerability reporting
This Policy describes general security practices and response principles and does not create a guarantee that any particular security control will always be available or effective.
2. Security Measures
Cry-Fi may implement reasonable technical, organizational, and administrative safeguards appropriate to the nature and risks of the Platform.
Depending on the circumstances, these measures may include:
Secure hosting and infrastructure practices
Access controls
Authentication and account-protection measures
Encryption or encrypted transmission where applicable
Security updates and maintenance
Technical logging and monitoring where appropriate
Fraud and abuse detection
Administrative and organizational security controls
Backup or recovery measures where appropriate
Cry-Fi may modify, replace, or improve its security measures as the Platform develops, technology changes, and security risks evolve.
3. User Security Responsibilities
Users and Listeners are responsible for taking reasonable steps to protect their accounts, devices, and access credentials.
This includes:
Keeping login credentials confidential
Using reasonably strong and unique passwords
Not sharing account credentials
Protecting personal devices from unauthorized access
Keeping devices and relevant software reasonably updated
Using only legitimate Cry-Fi access methods
Reporting suspected unauthorized account access
Keeping account and contact information reasonably accurate
Users should promptly notify Cry-Fi if they reasonably believe that their account has been compromised or used without authorization.
Cry-Fi may take reasonable steps to secure or restrict an account where unauthorized access is suspected.
4. Security Incidents
A security incident may include an actual or suspected event that could affect the confidentiality, integrity, or availability of Cry-Fi systems or information, including:
Unauthorized account access
Credential compromise
Unauthorized data access
Accidental data exposure
Malware or malicious activity
Website or Platform tampering
Unauthorized system changes
Service disruption
Exploitation of a security vulnerability
Other events that may materially affect Platform security
Cry-Fi may assess incidents based on their nature, scope, severity, credibility, and potential impact.
Not every technical issue, service interruption, or unsuccessful attack attempt will constitute a personal-data breach.
5. Third-Party Services
Cry-Fi may use third-party providers for services such as:
Hosting
Payment processing
Email delivery
Analytics
Advertising
Security
Authentication
Video or communication infrastructure
Other technology or operational services
These providers may maintain their own security controls, privacy practices, terms, and incident-response procedures.
Where a security incident involves a third-party provider, Cry-Fi may coordinate with that provider and take reasonable steps within its control to assess, contain, mitigate, or otherwise address the issue.
Third-party security incidents may be subject to the provider’s own notification and response obligations.
6. Security Incident Response
When Cry-Fi becomes aware of a potentially significant security incident, Cry-Fi may take reasonable steps, as appropriate to the circumstances, to:
Identify and assess the incident;
Determine potentially affected systems, accounts, or information;
Restrict affected systems or accounts where appropriate;
Contain or prevent unauthorized access;
Secure or restore affected systems;
Investigate the nature and potential scope of the incident;
Preserve relevant technical records;
Coordinate with relevant service providers or security specialists;
Take corrective or preventive measures; and
Notify affected individuals, authorities, or other parties where required or appropriate under applicable law.
The specific response will depend on the nature, severity, scope, and circumstances of the incident.
7. Personal-Data Breach Response
Where Cry-Fi determines that a security incident may constitute a personal-data breach, Cry-Fi may assess:
What information was affected;
Which individuals may be affected;
Whether the information was accessed, disclosed, altered, lost, or otherwise compromised;
The nature and severity of potential risks;
Whether containment or mitigation measures are necessary;
Whether notification is legally required;
Which authorities or other parties may need to be notified; and
What remedial or protective measures may be appropriate.
Cry-Fi will take actions required by applicable law and may take additional reasonable measures where appropriate.
8. User Notification
Where notification is required by applicable law, or where Cry-Fi reasonably determines that notification is appropriate, affected users may be notified through reasonable communication methods, including:
Email
Account notifications
Platform notices
Other appropriate communication channels
The timing, method, and content of any notification may depend on:
The nature of the incident;
The information affected;
Potential risks to individuals;
Applicable legal requirements; and
Whether notification could interfere with a legitimate investigation or security response.
Cry-Fi cannot guarantee that every security incident will result in individual notification where notification is not legally required or reasonably appropriate.
9. Law Enforcement & Regulatory Cooperation
Cry-Fi may cooperate with:
Law enforcement agencies
Government authorities
Regulatory bodies
Courts
Cybersecurity investigators
Other competent authorities
where required or legally permitted.
Cry-Fi may preserve or disclose relevant information where legally required or otherwise permitted under applicable law.
10. Security Logs & Evidence Preservation
Cry-Fi may retain relevant technical records, logs, account information, and other information relating to:
Security incidents
Unauthorized access
Fraud
Account compromise
Abuse or misconduct investigations
Platform security
Disputes
Legal or regulatory requirements
Retention will be handled in accordance with Cry-Fi’s Privacy Policy and Data Retention & Deletion Policy, subject to applicable law.
Preservation of information for security or legal purposes does not necessarily mean that the information will be retained indefinitely.
11. Responsible Vulnerability Disclosure
If you identify a potential security vulnerability affecting Cry-Fi, you should report it responsibly rather than publicly exploiting, selling, or disclosing the vulnerability before Cry-Fi has had a reasonable opportunity to assess it.
Reports should include, where reasonably possible:
A description of the suspected vulnerability;
The affected feature, endpoint, or system;
Steps necessary to reproduce the issue;
Relevant technical information; and
The potential security or privacy impact.
Reports should contain only the minimum information reasonably necessary to demonstrate the issue.
Cry-Fi may investigate legitimate security reports and take appropriate action.
You must not:
Access accounts or information belonging to other users;
Extract, copy, modify, or disclose personal information;
Disrupt Platform availability;
Deploy malware or other harmful code;
Conduct destructive testing;
Circumvent security controls for purposes unrelated to demonstrating the vulnerability; or
Continue testing after being asked to stop.
Unauthorized access, exploitation, disruption, data extraction, or security testing against Cry-Fi systems or third-party systems without appropriate authorization is prohibited.
If you unintentionally access information that does not belong to you while investigating a suspected vulnerability, stop further access, do not copy or disclose the information, and report the issue responsibly.
12. No Guarantee of Absolute Security
Cry-Fi takes reasonable security measures but cannot guarantee that:
The Platform will never be attacked;
Unauthorized access will never occur;
All vulnerabilities will be detected;
All security incidents will be prevented;
Third-party systems will always remain secure;
User devices or credentials will remain secure; or
Information transmitted over the internet will be completely risk-free.
Users should understand that internet-based services carry inherent security and privacy risks.
13. Limitation of Responsibility
To the fullest extent permitted by applicable law, Cry-Fi is not responsible for security incidents arising solely from circumstances outside its reasonable control, including certain criminal attacks, compromised user devices or credentials, or failures within independent third-party systems.
Cry-Fi will nevertheless make reasonable efforts, within its control and subject to applicable law, to respond to significant security incidents and mitigate their effects.
Nothing in this Policy excludes or limits liability that cannot legally be excluded or limited.
14. Security Improvements
Cry-Fi may periodically review and improve its:
Security controls
Authentication systems
Access controls
Monitoring mechanisms
Infrastructure
Fraud and abuse prevention measures
Incident-response procedures
Data-protection practices
Security practices may change as the Platform, technology, and threat landscape evolve.
Cry-Fi does not guarantee that any particular security feature or control will remain available indefinitely.
15. Relationship With Other Policies
This Policy should be read together with Cry-Fi’s other applicable policies, including:
Terms & Conditions
Privacy Policy
Data Retention & Deletion Policy
Safety & Reporting Policy
Content Moderation Policy
Code of Conduct
Community Guidelines
Listener Agreement
Listener Vetting & Verification Policy
Registration Terms
Booking Terms
Refund & Cancellation Policy
Personal-information handling, retention, deletion, and user privacy rights are further governed by Cry-Fi’s Privacy Policy and Data Retention & Deletion Policy.
16. Policy Changes
Cry-Fi may update this Policy from time to time to reflect changes in the Platform, security practices, technology, threat environment, or applicable legal requirements.
Updated versions become effective upon publication unless otherwise stated.
17. Contact
General matters:
Support:
Security or technical concerns:
