Trust

Security & Vulnerability Disclosure

Last updated: 19 August 2026.

Reporting a vulnerability

If you believe you have found a security vulnerability in our systems or in data we hold, please tell us. We welcome reports from security researchers and we will not pursue legal action against anyone who reports in good faith under this policy.

Email rollie@cornerstoneconsultingky.com with a description of the issue, the steps to reproduce it, and any supporting evidence. If you would like to encrypt your report, say so and we will provide a key.

What to expect

  • Acknowledgement within 2 business days.
  • An initial assessment and expected remediation timeline within 10 business days.
  • Notification when the issue is resolved, and credit for the discovery if you would like it.

Please do

  • Give us reasonable time to remediate before any public disclosure.
  • Limit testing to accounts and data you own or are authorised to test.
  • Stop immediately and tell us if you encounter personal data.

Please do not

  • Access, modify, exfiltrate or delete data that is not yours.
  • Run denial-of-service, spam or social engineering attacks, or physical testing of any kind.
  • Use automated scanning that degrades service availability.

How we handle data

  • Per-client separation. Each client's data is stored in an isolated environment and is never combined with another client's.
  • Encryption. Data is encrypted in transit and at rest.
  • Least privilege. Access is limited to the personnel delivering the engagement, and platform access is read-only.
  • Defined retention. Data is deleted at the end of the agreed retention period, on client instruction, or on a valid deletion request.
  • No model training. Client data is never used to train or fine-tune machine learning models. Our AI vendors are contractually bound to the same restriction, with zero data retention enabled.
  • Vendor control. Every sub-processor is engaged under a written agreement limiting processing to our documented instructions.

Platform access

We access client social accounts only through official platform APIs, under permissions the client grants and can revoke at any time from their own Business Manager. We never request passwords, we never post, comment, hide or delete on a client's behalf, and we do not scrape.

Incident notification

If we become aware of a breach affecting client or personal data, we will notify affected clients without undue delay and in any event within 72 hours of becoming aware, with what we know, what we are doing about it, and what we recommend.

Contact

Security: rollie@cornerstoneconsultingky.com
Privacy and data deletion: rollie@cornerstoneconsultingky.com