Account Protection
Session controls, MFA support, credential checks, and suspicious activity notifications help secure user accounts.
Security
Cofellow applies layered security controls across account access, platform operations, payments, and infrastructure to reduce risk and improve trust.
Effective date: February 28, 2026
Session controls, MFA support, credential checks, and suspicious activity notifications help secure user accounts.
Access restrictions, validation, rate limiting, and monitored write flows reduce abuse and unauthorized actions.
Security signals, logging, and response procedures are used to detect and address incidents quickly.
Our security approach includes preventative controls, detective monitoring, and operational response procedures designed for a multi-role transactional platform.
We support account verification workflows, optional multi-factor authentication controls, and role-based authorization boundaries to reduce unauthorized data and action access.
We use practical safeguards such as encrypted transit channels, restricted service access, and secure operational patterns for handling sensitive records.
Some security-critical operations involve third-party providers, including payment processors and identity verification vendors. We assess providers before use and limit shared data to what is necessary for each operation.
Automated and manual controls are used for abuse detection, including rate limiting, anti-bot checks, suspicious activity monitoring, and enforcement workflows.
We assess and prioritize vulnerabilities based on risk, with remediation timelines influenced by severity and exploitability.
We maintain incident response procedures for containment, mitigation, investigation, and communication in line with applicable legal requirements.
If you believe you found a security issue, please contact us promptly with reproducible details so we can investigate and remediate.
Please do not perform destructive testing, data exfiltration, or denial-of-service activity.
Report security concerns to [email protected] and include relevant logs, timestamps, and affected flows.
For account access or security concerns, contact support quickly through our support channels.