Legal
Law Enforcement Guidelines
[ SECURITY POLICY
Effective Date: [08/01/2026]
VIA BOCA LLC is committed to protecting Estate Scorer, its users, and customer information through commercially reasonable administrative, technical, and organizational safeguards.
While no security program can guarantee absolute protection, Estate Scorer is designed with multiple layers of security intended to reduce risk and protect the confidentiality, integrity, and availability of the Service.
________________________________________
1. Security Principles
Our security program is built upon the following principles:
• Defense in Depth
• Least Privilege
• Secure by Default
• Risk-Based Security
• Continuous Improvement
• Incident Preparedness
• Data Minimization
• Privacy by Design
________________________________________
2. Encryption
Estate Scorer uses encryption technologies designed to protect data.
These may include:
• TLS encryption for data transmitted over the Internet;
• HTTPS connections;
• encryption at rest where commercially appropriate;
• encrypted cloud storage;
• encrypted backups where supported.
________________________________________
3. Access Control
Access to production systems is limited based upon business necessity.
Controls may include:
• role-based permissions;
• least privilege access;
• authentication requirements;
• logging of privileged actions;
• periodic access reviews.
Only authorized personnel receive access to customer information required to perform their responsibilities.
________________________________________
4. Authentication
Estate Scorer maintains authentication mechanisms intended to reduce unauthorized access.
Security controls may include:
• secure password handling;
• session management;
• login monitoring;
• suspicious login detection;
• rate limiting;
• account lockout after repeated failed authentication attempts.
Users are responsible for protecting their own passwords and account credentials.
________________________________________
5. Infrastructure Security
Estate Scorer is hosted using reputable cloud infrastructure providers.
Infrastructure protections may include:
• network segmentation;
• firewalls;
• infrastructure monitoring;
• redundancy;
• availability protections;
• automated deployment controls;
• vulnerability management.
________________________________________
6. Monitoring
The Company may monitor systems to detect:
• suspicious activity;
• intrusion attempts;
• denial-of-service attacks;
• unusual account behavior;
• payment fraud;
• abnormal traffic;
• infrastructure failures.
Monitoring is performed to improve security and platform reliability.
________________________________________
7. Software Updates
Estate Scorer continuously deploys software updates intended to improve:
• security;
• performance;
• reliability;
• functionality;
• compatibility.
Security updates may be deployed without prior notice.
________________________________________
8. Vendor Security
The Company works with third-party providers that are expected to maintain appropriate security standards.
These providers may include:
• payment processors;
• cloud providers;
• AI providers;
• analytics vendors;
• customer support vendors.
Each provider maintains independent security programs.
________________________________________
9. Incident Response
The Company maintains procedures designed to:
• identify incidents;
• investigate security events;
• contain threats;
• recover operations;
• notify affected parties where legally required;
• improve future security.
________________________________________
10. User Responsibilities
Users should:
• maintain strong passwords;
• avoid password sharing;
• use secure devices;
• install software updates;
• report suspicious activity promptly;
• protect account credentials.
Failure to follow reasonable security practices may increase security risks.
________________________________________
END SECURITY POLICY
________________________________________
RESPONSIBLE VULNERABILITY DISCLOSURE POLICY
1. Purpose
VIA BOCA LLC appreciates responsible security research.
If you discover a potential security vulnerability affecting Estate Scorer, we encourage responsible disclosure.
________________________________________
2. Reporting
Please report vulnerabilities to:
support@estatescorer.com
Include whenever possible:
• description of the issue;
• affected pages;
• proof of concept;
• reproduction steps;
• screenshots;
• suggested remediation.
________________________________________
3. Good Faith Research
Security researchers acting in good faith and following this Policy will generally not be subject to legal action by VIA BOCA LLC for authorized testing that complies with this Policy.
This protection does not apply to activities involving:
• data theft;
• destruction of information;
• denial-of-service attacks;
• social engineering;
• physical attacks;
• extortion;
• malware deployment;
• unauthorized access to customer accounts.
________________________________________
4. Rules
Researchers should:
• avoid accessing unnecessary personal information;
• avoid disrupting the Service;
• stop testing after confirming a vulnerability;
• provide reasonable time for remediation before public disclosure.
________________________________________
5. Out of Scope
The following are generally outside the scope of this Policy:
• spam reports;
• social engineering;
• phishing;
• physical security;
• attacks against third-party providers;
• denial-of-service testing;
• vulnerabilities requiring compromised devices.
________________________________________
6. No Bug Bounty
Unless expressly announced, VIA BOCA LLC does not operate a bug bounty program.
Submission of a report does not create any entitlement to compensation.
________________________________________
END RESPONSIBLE DISCLOSURE POLICY
________________________________________
LAW ENFORCEMENT REQUEST POLICY
1. Purpose
VIA BOCA LLC is committed to protecting user privacy while complying with applicable legal obligations.
This Policy explains how the Company responds to requests from governmental authorities and law enforcement agencies.
________________________________________
2. Valid Legal Process
The Company generally requires valid legal process before disclosing customer information.
Examples include:
• subpoenas;
• court orders;
• search warrants;
• other legally binding requests.
Requests are reviewed for legal sufficiency before information is disclosed.
________________________________________
3. Emergency Requests
Where applicable law permits, the Company may disclose limited information in good-faith emergency circumstances involving an imminent threat of death or serious physical harm.
________________________________________
4. User Notification
Unless prohibited by law or where doing so would create a risk of harm, interfere with an investigation, or violate a court order, VIA BOCA LLC may notify affected users before responding to legal requests.
________________________________________
5. Scope of Disclosure
When disclosure is legally required, the Company seeks to disclose only the information reasonably necessary to satisfy the request.
________________________________________
6. Preservation Requests
The Company may preserve relevant information where legally required while awaiting formal legal process.
Preservation does not necessarily mean disclosure.
________________________________________
7. International Requests
Requests from foreign governmental authorities will generally be evaluated in accordance with applicable U.S. law and any relevant international legal process.
________________________________________
8. Transparency
Where legally permissible, VIA BOCA LLC may periodically publish aggregated transparency information regarding:
• number of legal requests received;
• categories of requests;
• general response statistics.
Publication of such information is entirely at the Company's discretion.
________________________________________
9. Contact
Government agencies may submit lawful requests through:
support@estatescorer.com
Improperly submitted requests may be rejected.
]