INFORMATION SECURITY POLICY
1. General Provisions
1.1. This Information Security Policy (the «Policy») sets out the objectives, principles and measures for ensuring information security in the operation of the website crazypub.gg (the «Site») and in the processing of information, including personal data of Users.
1.2. The Policy is developed in accordance with Federal Law No. 152-FZ «On Personal Data», Federal Law No. 149-FZ «On Information, Information Technologies and Information Protection», and other applicable information security regulations of the Russian Federation.
1.3. The Policy applies to all information assets of the Site: source code, databases, server infrastructure, employee workstations, communication channels and storage media.
2. Goals and Principles
2.1. The goals of information security are:
- protection of confidentiality, integrity and availability of information;
- prevention of unauthorised access to Users' data;
- timely detection of and response to security incidents;
- minimisation of the risks of data leakage, loss and distortion;
- compliance with the laws of the Russian Federation.
2.2. Information security is based on the principles of legality, comprehensiveness, continuity, timeliness, reasonable sufficiency and personal accountability.
3. Technical Safeguards
3.1. All data transmission between the User and the Site is performed exclusively over the secure HTTPS protocol using TLS version 1.2 or higher.
3.2. User passwords are not stored in plain text; modern salted hashing algorithms are used for authentication.
3.3. User sessions are protected by signed tokens (JWT) with a limited lifetime and server-side validation.
3.4. Access to server infrastructure is restricted by a firewall and performed only via secure channels (SSH with key authentication) from a limited set of IP addresses.
3.5. Software components of the Site are regularly updated to address known vulnerabilities. Automated tools are used to monitor dependencies for vulnerabilities.
3.6. Backups of databases are performed at least once per day; copies are stored in encrypted form on a separate protected resource.
3.7. Protection is implemented against common attacks: SQL injection (parameterised queries), cross-site scripting (XSS), cross-site request forgery (CSRF), brute force (rate-limiting on sensitive endpoints).
3.8. Payment data (card numbers, CVV/CVC, PIN codes) is not received, processed or stored on the Site. All payment operations are performed on payment pages of PCI DSS certified payment systems.
4. Payment Operations Security
4.1. Payments on the Site are made via certified payment systems that hold a confirmed certificate of compliance with the PCI DSS standard regarding the storage, processing and transmission of cardholder data. The PCI DSS bank card security standard is supported by international payment systems.
4.2. Confidential User data required for payment (card details, registration data, etc.) does not reach the online store (the Site's servers) - it is processed on the side of the payment system's processing centre and is fully protected.
4.3. Transmission of payment data between the User and the payment system is performed over a secure connection using TLS cryptographic protocols. If the User's bank card is enrolled in 3D-Secure, the User is automatically redirected to the issuing bank's page to complete authentication.
4.4. The Administration takes all reasonable measures to protect the integrity and availability of payment information, including keeping transaction logs, monitoring and timely detection of suspicious activity.
5. Organisational Measures
5.1. Access to information systems of the Site is granted on the principle of least privilege: each employee receives only the rights necessary to perform their tasks.
5.2. All privileged actions (changes to User data, access to financial information, changes to access rights) are recorded in an audit log.
5.3. Accounts of employees who have ceased cooperation with the Administration are blocked within 24 hours.
5.4. Internal information is exchanged between employees via secure communication channels. Transmission of confidential information via insecure channels and public messengers is prohibited.
5.5. Employees with access to Users' personal data are familiarised with the requirements of personal data legislation and bear personal responsibility for compliance with them.
6. Personal Data Protection
6.1. Processing of Users' personal data is performed in accordance with the Privacy and Personal Data Processing Policy.
6.2. Personal data is stored in databases located in the territory of the Russian Federation, in accordance with Part 5 of Article 18 of Federal Law No. 152-FZ.
6.3. Access to Users' personal data is granted to a limited group of persons whose actions are logged.
6.4. The storage period for personal data is determined by the purposes of its processing and does not exceed the period stipulated by applicable law.
7. Incident Response
7.1. An information security incident is any event that has led or may lead to a breach of the confidentiality, integrity or availability of information.
7.2. Reports of discovered vulnerabilities and incidents shall be sent to the e-mail address: partnership@crazypub.gg with the subject line «Security Incident».
7.3. The Administration considers received reports within 3 (three) business days from receipt and takes measures to eliminate the incident.
7.4. In the event of a confirmed incident resulting in unauthorised access to personal data, the Administration notifies Users and the authorised body for the protection of the rights of personal data subjects in the manner and within the timeframes established by the laws of the Russian Federation.
8. Responsible Vulnerability Disclosure
8.1. The Administration welcomes responsible disclosure of vulnerabilities by information security researchers.
8.2. When a vulnerability is discovered, the researcher shall:
- promptly report it to partnership@crazypub.gg;
- not exploit the discovered vulnerability to access data not belonging to the researcher;
- not publish information about the vulnerability before it is remediated and disclosure is coordinated with the Administration.
8.3. Actions of the researcher performed in accordance with this section and not resulting in damage shall not be considered a violation of the terms of use of the Site.
9. Final Provisions
9.1. This Policy is subject to periodic review in light of changes in legislation, technology developments and the emergence of new security threats.
9.2. The current version of the Policy is published on the Site at https://crazypub.gg/security and takes effect from the date of its publication.
9.3. For any questions related to information security, the User may contact: partnership@crazypub.gg.