1. Measures
We apply security measures appropriate to the risk of a freelance marketplace that handles identity, messages, and payments metadata, including: TLS in transit; access control and least privilege; session cookies; rate limiting; security headers; infrastructure security from Cloudflare and Supabase; and staff access logging as implemented. Last updated 1 September 2026.
2. Your responsibilities
- Use a unique password and keep it secret. Enable stronger authentication when offered.
- Do not share accounts. Offboard people who leave your organisation.
- Treat meeting links and file URLs as confidential.
- Keep your devices and browsers updated.
- Do not upload malware or attempt to probe the Platform except via the disclosure channel below.
3. Incidents
If we become aware of a personal-data breach, we will notify affected users and authorities as required (including GDPR 72-hour authority notification where applicable, and state/federal US, POPIA, LGPD, PIPL, and other clocks). Report suspected incidents to security@sydgig.com.
4. Vulnerability disclosure
Email security@sydgig.com with a technical description. Do not access other users' data, degrade the service, or demand payment. We will not pursue civil claims against researchers who act in good faith, stay within this policy, and give us a reasonable chance to fix issues before publication. This is not a paid bug-bounty unless we later publish one.
5. Legal overlay
Reasonable-security duties exist in many laws (GDPR Art. 32, UK DPA, CCPA/CPRA, NY SHIELD, LGPD, POPIA, APPI, PIPL, and others). This page describes practice; it is not a certification (ISO 27001, SOC 2) unless we separately publish an attestation.
