Security & Compliance
At Crescendo Systems, information security and data governance are at the core of everything we do. We are committed to protecting the integrity of our systems and the absolute confidentiality of our partners’ data within the DigiWeb platform.
Responsible Vulnerability Disclosure
If you are a security researcher, ethical hacker, or system user and believe you have identified a potential security vulnerability within DigiWeb, we welcome your report. We operate a responsible disclosure policy to ensure all security flaws are safely received, evaluated, and remediated.
How to Report a Finding
Please email our monitored security operations team directly at security@crescendocloud.co.uk. To help us triage your report efficiently, please include:
- A clear, descriptive summary of the potential vulnerability.
- Detailed, step-by-step instructions or a proof-of-concept (PoC) to help our engineering team reproduce the issue.
- Your contact information if you wish to receive progress updates.
Our Commitment (Remediation SLA)
- Acknowledgment: We will formally acknowledge receipt of your report within 48 business hours.
- Triage: Our core engineering team will validate and risk-rate the vulnerability within 5 working days.
- Remediation: Critical vulnerabilities are prioritised for immediate emergency hotfixing and deployment via our secure CI/CD pipelines.
Note: We ask that you give us a reasonable opportunity to remediate any findings before making them public, and that you do not access, alter, or destroy any production customer data during your research.
Request Access to the DigiWeb Compliance Pack
Please complete the secure form below to request the comprehensive Security & Compliance Portfolio for DigiWeb and Crescendo Systems Limited.
Important Notice: Because these documents contain detailed internal system architecture, access is restricted and as such, all requests undergo strict manual vetting. You must use your official work email address (e.g., a corporate domain). Requests originating from public providers like Gmail, Outlook, or Hotmail will be automatically rejected.
