Security Policy
Last Updated: 8 February 2025
Pekulav is committed to protecting the security of our platform, systems, and the data entrusted to us by our users. This Security Policy describes the technical and organisational measures we employ to safeguard information and maintain the integrity, availability, and confidentiality of our services available at mekarou.com.
By using our platform, you acknowledge that you have read and understood this policy. We encourage you to review it periodically, as we update it to reflect improvements to our security practices.
1. Scope
This policy applies to all systems, infrastructure, applications, and data managed by Pekulav in connection with the delivery of our online masterclass platform. It covers:
- All web-based services and interfaces operated under mekarou.com
- Internal systems and tools used to deliver and maintain the platform
- Data processed on behalf of registered users, instructors, and visitors
- Third-party integrations and service providers connected to our infrastructure
2. Information We Protect
Our security controls are designed to protect the following categories of information:
- Account credentials - usernames, passwords, and authentication tokens
- Personal information - names, email addresses, and contact details provided during registration
- Payment data - billing information processed through our payment providers
- Usage and behavioural data - interaction logs, session data, and learning progress records
- Communications - messages, support requests, and feedback submitted through the platform
3. Security Measures
3.1 Data Encryption
All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS). We enforce HTTPS across all pages and services. Sensitive data stored within our systems is encrypted at rest using industry-standard encryption algorithms. Passwords are never stored in plain text and are processed using strong one-way hashing functions.
3.2 Access Controls
Access to production systems and user data is restricted to authorised personnel only. We apply the principle of least privilege, ensuring that each team member has access only to the resources necessary for their specific role. Administrative access requires multi-factor authentication and is subject to regular review.
3.3 Network Security
Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation. We monitor network traffic for anomalous activity and apply rate limiting and filtering to mitigate abuse and denial-of-service attempts.
3.4 Application Security
We follow secure software development practices throughout our development lifecycle, including:
- Code review and security testing prior to deployment
- Protection against common vulnerabilities including SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF)
- Regular dependency audits and timely application of security patches
- Input validation and output encoding across all user-facing interfaces
3.5 Authentication and Session Management
User accounts are protected through secure authentication mechanisms. Sessions are managed using time-limited tokens that are invalidated upon logout. We support and encourage the use of strong, unique passwords and may offer multi-factor authentication options to further protect user accounts.
3.6 Infrastructure and Hosting
Our platform is hosted on reputable cloud infrastructure providers that maintain their own comprehensive security certifications and compliance programmes. Physical access to data centres is controlled and monitored by our hosting providers. We configure our cloud environments in accordance with security best practices, including isolated environments, automated backups, and access logging.
3.7 Data Backups
We perform regular automated backups of critical data. Backups are stored securely and tested periodically to ensure they can be restored reliably. Retention periods for backups are defined in accordance with our operational and data management requirements.
4. Third-Party Service Providers
We work with carefully selected third-party vendors to deliver certain aspects of our service, including payment processing, email delivery, and analytics. We evaluate the security posture of these providers before engagement and require that they maintain appropriate security standards. Data shared with third parties is limited to what is strictly necessary for the purpose of the service they provide.
We do not sell user data to third parties and do not permit third-party providers to use your data for purposes beyond those we have authorised.
5. Security Monitoring and Incident Response
5.1 Monitoring
We maintain continuous monitoring of our systems and infrastructure. Logs are collected, stored securely, and reviewed to detect unauthorised access, unusual behaviour, or potential security events. Automated alerts are configured to notify our team of conditions that may indicate a security incident.
5.2 Incident Response
We maintain an incident response process to handle security events in a timely and structured manner. In the event of a confirmed security incident that affects user data, we will:
- Investigate and contain the incident as quickly as possible
- Assess the nature and scope of the impact
- Notify affected users and relevant authorities as required and without undue delay
- Take corrective action to prevent recurrence
- Document the incident and our response for internal review
Notifications will be sent to the email address associated with your account. We encourage users to keep their contact information up to date.
6. User Responsibilities
Security is a shared responsibility. We ask that all users of our platform take reasonable steps to protect their own accounts and data:
- Use a strong, unique password for your Pekulav account and do not share it with others
- Log out of your account when using shared or public devices
- Keep your registered email address current so that security notifications reach you
- Report any suspicious activity related to your account promptly to our support team
- Do not attempt to access systems, accounts, or data that you are not authorised to access
- Ensure that any device you use to access the platform is reasonably secured and kept up to date
7. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you believe you have discovered a security issue affecting our platform, we ask that you contact us directly before making any information public. Please provide sufficient detail to allow us to reproduce and investigate the issue.
To report a vulnerability, please contact us at:
Email: support@mekarou.com
Phone: +353 1 810 3439
We commit to acknowledging your report promptly, investigating it in good faith, and keeping you informed of our progress. We ask that you do not access, modify, or delete any data beyond what is necessary to demonstrate the vulnerability, and that you refrain from disrupting our services during your research.
8. Organisational Security Practices
Internally, Pekulav maintains security through the following organisational measures:
- Security awareness training for all team members with access to systems or data
- Clear policies governing the acceptable use of systems and data
- Regular internal review of access rights and user privilege levels
- Documented procedures for onboarding and offboarding personnel with system access
- Confidentiality obligations for all personnel handling user data
9. Retention and Deletion
We retain data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable obligations, or to resolve disputes. When data is no longer required, it is securely deleted or anonymised. Users may request the deletion of their account and associated personal data by contacting our support team.
10. Updates to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this page and, where appropriate, notify users through the platform or by email.
Continued use of the platform following the publication of an updated policy constitutes your acceptance of the revised terms. If you do not agree with any changes, you should discontinue use of the platform and contact us to request deletion of your account.
11. Contact Us
If you have any questions, concerns, or requests relating to this Security Policy or our security practices, please contact us using the details below:
Pekulav
Tievebane, Co. Donegal, F93 TW54, Ireland
Email: support@mekarou.com
Phone: +353 1 810 3439
Website: mekarou.com