Our Responsibilities and Policies

Corporate Social Responsibility

We believe that our success should be defined by both our financial performance and the positive contribution we make to society.

People

We celebrate Diversity, Inclusivity and Equality in our workplaces and reflect these values in human resource management and recruitment in all of our offices. There is always more that can be done but we strive to be a good employer and to enhance the welfare of our teams.

Planet

We believe in sustainability. It is important to us that our teams and the companies we work with consider environmental and ethical factors when taking business decisions. We actively source our consumable supplies from environmentally responsible sources.

Profit

We train our teams to conduct business in a responsible manner, promoting environmental standards, protecting labour and human rights and maintaining ethical standards.

Our CSR Goal

It is our goal to remain socially accountable to our clients, our employees and the communities where we do business. We consistently incorporate best practice principles of Corporate Social Responsibility in how we conduct our business. Our Board has documented governance processes to safeguard against wrongdoing and we conduct due diligence to ensure we make socially responsible investments. We actively promote awareness in our teams of laws and regulations that protect the environment, labour and human rights and operate a culture of openness to report any concerns, where relevant maintaining anonymity, regarding practices in the business or within our supply chain.

Our Framework

In adopting our CSR policy, we reviewed: the UN Global Compact’s principles covering human rights, labour, the environment and anti-corruption; the Universal Declaration of Human Rights of the United Nations; the OECD Guidelines for Multinational Enterprises.

Modern Slavery

Although Com Laude falls below the threshold under section 54 Modern Slavery Act 2015 which requires publication of a modern-day slavery statement, we fully understand our obligations to comply with this legislation. We consider matters of Slavery and Human Trafficking when entering into contractual arrangements as part of a zero-tolerance approach that aligns with our values and pass this requirement contractually down our supply chain.

For further information, contact any of the leaders of Com Laude.

Vulnerability Disclosure Policy

Com Laude works with brands to maximise their ability to do business online. We do this through strategic domain name management, protecting against cyber-attacks, and counteracting digital brand infringement. As part of this we are committed to providing secure, stable and resilient infrastructure and systems for our clients.

Scope

This policy applies to persons who identify vulnerabilities in our systems and who are not affiliated with Com Laude and its related corporate entities. If you are a client of ours, we recommend you contact your client manager.

Definitions:

For the purpose of this policy, the following definitions apply.

Com Laude System: any system that is owned, controlled or managed by the Com Laude Group, including its related corporate entities.

Finder: any legal or natural person who identifies a potential Vulnerability in the Com Laude System.

Reporter: the person who originates the message of a potential Vulnerability to Com Laude (often the same person as a Finder).

Vulnerability: a flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s security policy.

Reporting a Vulnerability

If you find a Vulnerability in a Com Laude System, we ask that you report it to us at vulnerabilities@comlaude.com straight away so that we can remediate the Vulnerability as quickly as possible. We ask that Finders and Reporters:

a. do not disclose the Vulnerability to any other party to mitigate the risk of others maliciously utilising the Vulnerability;
b. do not exploit a security issues that you discover for any reason;
c. make a good faith effort to avoid privacy violations and disruptions to others, including but not limited to unauthorised access to or destruction of data and interruption or degradation of our services; and
d. do not access user data or company data including but not limited to personally identifiable information and data relating to an identified or identifiable natural person as Finders and Reports are not authorised to do so.

When reporting a Vulnerability, we ask that you include screenshots, a description of the process you used to identify the Vulnerability, the time and date of discovery, and any other information that would allow us to replicate or otherwise verify the Vulnerability. After reporting a Vulnerability, we ask that Finders and Reporters do not engage in further scrutiny or exploitation of the Vulnerability.

Legal Action

We take cyber security seriously at Com Laude and always appreciate those who take the time to report Vulnerabilities. We will not take legal action against Finders or Reporters if they adhere to this policy and if:

a. they do not compromise the availability, security or privacy of Com Laude Systems; or
b. they have received prior written permission from Com Laude to engage in vulnerability or penetration testing and the identification of the Vulnerability is within the scope of our written permission.

This is contingent on Finders and Reporters:

a. Not violating any applicable laws or regulations; and
b. Not publicly sharing the Vulnerability or related details until Com Laude has remediated the Vulnerability. For the avoidance of doubt, this does not permit Finders or Reporters to share details of a Vulnerability unless Com Laude provides written permission in advance to do so.

Remediating the Vulnerability

Once we have verified the Vulnerability, we will follow our internal processes to remediate the Vulnerability. The time to develop and deploy a remediation for a Vulnerability will be on a case by case basis and will be based largely on our own internal categorisation of the impact and exploitability of the Vulnerability. We will inform you after we have deployed a remediation for the Vulnerability.

Public Awareness of Vulnerabilities

The majority of the Com Laude Systems are internal or client facing and not available to the public. In most instances we will only share the details of the Vulnerability with the affected parties, that is, our clients and staff. However, this will depend on the nature of the Vulnerability. For example, we would always disclose data breaches where required by law.

We use cookies on this site to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies.

OKNo; give me more information