✌️ Darmowe narzędzie do sprawdzania backlinków Collaborator Sprawdź backlinki

Information Security Policy

Effective date: 04 March 2025

Information Security Policy

Collaborator Platform

1. Introduction

The Collaborator platform (collaborator.pro) is operated by I.M. COLLABORATOR LTD, a company incorporated under the laws of the Republic of Cyprus, registration number HE 403087, with its registered office at Peiraios, 30, 1st floor, Flat / Office 1, Strovolos, 2023, Nicosia, Cyprus. In this policy, "Collaborator" refers to I.M. COLLABORATOR LTD.

Collaborator (collaborator.pro) is a content marketing and link-building marketplace that connects advertisers with publishers worldwide. Our platform enables advertisers to discover, order, and manage content placements on publisher websites, while publishers receive and fulfil placement orders through their Collaborator accounts.

Given the nature of our business – where two distinct parties interact, share information, and transact through a single platform – the security of user data, account information, and transaction records is a top priority. Collaborator has established a formal internal information security program covering access management, infrastructure protection, incident response, backup and recovery, and personnel security. This document summarizes our security posture for clients, publishers, and partners.

This document is provided for general information about Collaborator's security practices. Nothing in this document shall be construed as an offer, warranty, or contractual commitment, or as creating rights for any third party. Where an agreement between Collaborator and a counterparty addresses a matter covered here, that agreement prevails.

2. How Data Flows on the Collaborator Platform

Collaborator operates as an intermediary marketplace. We do not publish content ourselves – we facilitate transactions between advertisers and publishers. Understanding how data is handled between platform participants is central to our security approach.

Advertiser and Publisher Profile Visibility

When an advertiser places an order with a publisher, certain profile information is shared between the two parties to facilitate the business relationship – including company name, campaign details, and order specifications. Collaborator limits this visibility to what is operationally necessary. Sensitive account data, billing details, and private credentials are never exposed between parties.

Content and Placement Data

Content briefs, placement requirements, and published URLs are shared between advertisers and publishers through the platform. Publishers retain full control over their own websites; Collaborator does not have administrative or CMS access to publisher websites. Placement verification is conducted by checking publicly accessible URLs only.

What Collaborator Does Not Do

  • Does not access publisher website backends, CMS systems, or admin panels
  • Does not share one user's private account or billing data with another user
  • Does not sell user data to third parties for any purpose
  • Does not store full payment card details on its own servers

3. Data We Collect and Process

Account and Profile Data

  • Name, company name, email address, and account credentials for registered users
  • Publisher website URLs, niche categories, traffic metrics, and pricing submitted by publishers
  • Advertiser campaign preferences, target markets, and content requirements

Transaction and Order Data

  • Order history, content placement records, and communication logs between advertisers and publishers
  • Transaction metadata (IDs, amounts, payment status) – full card details are not stored by Collaborator directly
  • Invoice and billing records retained for accounting and legal compliance purposes

Technical and Usage Data

  • IP addresses, device information, and session data collected for security and fraud prevention
  • Platform activity logs used for dispute resolution, abuse prevention, and service improvement

4. Infrastructure & Cloud Security

Collaborator's platform is hosted on cloud infrastructure across multiple providers, including Amazon Web Services (AWS), DigitalOcean, OVH and Hetzner. This multi-provider approach ensures geographic redundancy and eliminates single points of failure.

  • All production systems are deployed within isolated virtual private cloud (VPC) environments with strict network segmentation
  • Firewalls and security groups deny all inbound traffic by default; only explicitly authorized services and ports are permitted
  • Infrastructure is monitored continuously using centralized tooling with automated alerting for anomalous activity, access changes, and service availability
  • SSH access logs, web server logs, and system service logs are retained for 30 days for security audit and incident investigation purposes

5. Data Protection & Encryption

  • All data transmitted between users and the Collaborator platform is encrypted in transit using TLS 1.2 or higher
  • Sensitive data stored within our systems is encrypted at rest
  • User passwords are stored using one-way cryptographic hashing – plaintext passwords are never stored or recoverable
  • Payment data: Collaborator stores only transaction metadata. Full card details are processed and stored exclusively by our certified third-party payment processor(s) and are never transmitted to or stored on Collaborator's own servers

6. Backup & Disaster Recovery

Collaborator maintains a documented backup and disaster recovery program with defined recovery objectives.

  • Database backups are performed automatically every 24 hours
  • Backups are replicated to three independent external storage locations: Amazon Web Services S3, a dedicated DigitalOcean server, and a dedicated OVH server – providing geographic and provider-level redundancy
  • Recovery Time Objective (RTO): up to 4 hours for critical systems
  • Recovery Point Objective (RPO): up to 24 hours
  • The RTO and RPO stated above are internal planning targets measured under normal operating conditions and do not constitute a service level guarantee
  • Recovery procedures are tested at least quarterly to verify that data can be successfully restored
  • Backup storage is access-controlled and isolated from production environments

7. Access Control & Identity Management

  • Role-based access control (RBAC) is applied across all internal systems: each employee is granted only the access required for their specific role (principle of least privilege)
  • Every employee and contractor has an individual account – shared credentials are not permitted
  • Multi-factor authentication (MFA) is required for all access to critical systems and production infrastructure
  • All administrative actions on production systems are logged and auditable
  • Access rights are reviewed at least quarterly and revoked immediately upon employee or contractor offboarding – on the last working day at the latest
  • Urgent offboarding (terminations for cause) triggers immediate access revocation at any time of day

8. User Data Isolation & Marketplace Security

As a two-sided marketplace, Collaborator applies specific controls to ensure that advertiser and publisher data remains appropriately isolated:

  • Each user account operates within a secure session; users can only access data associated with their own account
  • Order and campaign data is visible only to the specific advertiser and publisher involved in that transaction
  • Publisher website credentials and CMS access are never requested by or transmitted to Collaborator
  • Advertiser billing information is not visible to publishers, and vice versa
  • Platform access logs enable detection of unauthorized attempts to access other users' data

9. Vulnerability Management & Patch Management

  • Security patches for server operating systems and services are applied on a priority-risk basis; critical patches are applied without delay
  • Application dependencies and third-party libraries are monitored for known vulnerabilities and updated as required
  • Application code is reviewed for common security vulnerabilities during development
  • Security assessments and penetration testing are conducted periodically to evaluate the effectiveness of controls
  • Where a patch cannot be immediately applied, compensating controls are implemented (network segmentation, enhanced logging, WAF rules, or temporary feature isolation) until remediation is complete

10. Security Incident Response

Collaborator maintains a documented incident response plan with defined roles, escalation paths, and response time targets based on incident severity.

Incident Classification

  • P1 – Critical: major service outage, confirmed data breach, or compromise of production administrator credentials. Escalation: immediate, 24/7
  • P2 – High: compromise of a single account, backup failure, or malicious activity on a system node. Escalation: within 1 hour
  • P3 – Medium: isolated phishing attempt, configuration non-compliance. Escalation: within 1 business day
  • P4 – Low: observational findings, minor logging improvements. Resolution: as scheduled

Response Process

  • Upon detection, the incident is reported immediately through the designated internal channel and classified by severity
  • Initial containment actions are taken: access revocation, node isolation, credential rotation, traffic restriction
  • Evidence is preserved – logs, timelines, snapshots – before any remediation actions are taken
  • Following containment, root cause analysis is conducted and corrective actions are defined and tracked
  • In the event of a data breach affecting user data, Collaborator will notify affected users promptly in accordance with applicable law and contractual obligations

11. Personnel Security & Training

  • All employees and contractors sign confidentiality agreements before receiving system access
  • New employees receive security onboarding training before full access is granted, covering password practices, phishing awareness, data handling, and incident reporting
  • Security awareness training is conducted annually for all staff with system access
  • Additional targeted training may be assigned following security incidents or policy changes
  • Offboarding procedures include immediate revocation of all credentials, tokens, VPN access, repository access, and cloud service permissions

12. Third-Party Vendors & Sub-Processors

Collaborator works with third-party providers for infrastructure hosting, payment processing, and other platform functions. The following controls apply to all third-party relationships:

  • New vendors with access to customer data or production systems are assessed for security posture and contractual compliance before engagement
  • All sub-processors handling personal data are bound by contractual data protection obligations
  • Contractors receive only temporary, scoped access with a defined purpose and are subject to the same security requirements as employees
  • Payment processors used by Collaborator operate under PCI DSS certification; full payment card data is processed exclusively within their certified environments
  • Third-party integrations are periodically reviewed for continued necessity and security compliance

13. Monitoring & Logging

Collaborator operates a centralized monitoring and logging infrastructure to enable early detection of security events and service anomalies.

  • Authentication events, access rights changes, administrative actions, configuration changes, and service errors are captured in centralized logs
  • Automated alerts are configured for critical events including access changes, backup failures, deployment errors, credential changes, and abnormal load patterns
  • Infrastructure logs (SSH access, web server, system services) are retained for 30 days
  • Log access is restricted to authorized personnel; logs cannot be modified or deleted without an approved process

14. Privacy & Regulatory Compliance

Collaborator processes personal data of users in Ukraine, the European Union, and other jurisdictions, in compliance with applicable data protection laws including the Ukrainian Law on Personal Data Protection and the EU General Data Protection Regulation (GDPR).

  • Data is collected and processed only for specified, legitimate purposes with a valid legal basis
  • Personal data is not retained beyond the period necessary for its original purpose, unless required by applicable law
  • Users have the right to access, correct, and request deletion of their personal data – requests can be submitted to [email protected] 
  • Collaborator does not sell personal data of advertisers, publishers, or any other platform users to third parties
  • For full details on data processing practices, please refer to Collaborator's Privacy Policy at collaborator.pro 

15. Standards Alignment & Certification

This section sets out Collaborator's position regarding certification under international information security standards.

Collaborator's information security program is structured with reference to established international standards, including ISO/IEC 27001. As at the date of this policy, the program has not been submitted for formal certification under ISO/IEC 27001 or ISO/IEC 27701, nor for a SOC 2 or SOC 3 attestation. 

Certification under these standards is voluntary: the GDPR requires technical and organisational measures appropriate to the risk, and treats certification as one means of demonstrating compliance rather than as a requirement.

Collaborator keeps the merits of formal certification under review in light of the scale of its operations, client requirements, and regulatory developments. Any change in certification status will be reflected in a subsequent version of this policy.

In assessing whether certification is warranted, Collaborator takes into account the nature of the information processed on the platform:

  • Collaborator does not process special categories of personal data, such as health, biometric, or genetic data
  • Collaborator does not store full payment card details, which substantially reduces the scope of PCI DSS requirements applicable to Collaborator
  • The personal data processed is limited to what is necessary to operate the marketplace: contact details of corporate users, order parameters, and transaction metadata

The following measures support Collaborator's security posture:

  • Collaborator's infrastructure is hosted with major cloud providers that maintain their own independent security certifications
  • Payment processing is handled by providers operating under industry-standard card data security compliance
  • The measures described in this policy are documented in internal procedures and reviewed periodically.

16. Policy Review & Contact

This policy is reviewed and updated following significant changes to Collaborator's infrastructure, operations, or applicable legal requirements, and at least annually. The current version is published at collaborator.pro.

For questions regarding this policy or Collaborator's security practices, please contact: [email protected]

Collaborator reserves the right to update its security practices at any time. This document does not disclose confidential infrastructure details, internal credentials, or proprietary system configurations.

Zgodnie z naszą polityką dotyczącą plików cookie przetwarzamy pliki cookie, aby zapewnić użytkownikom najlepszą obsługę.