SECURITY FIRST

Security Disclosures

At Royal Emerging, security is not an afterthought — it's a core principle. We are committed to protecting our clients, their data, and our infrastructure through proactive security practices and transparent vulnerability management.

Last Updated: October 1, 2026

1. Our Security Commitment

Royal Emerging follows industry-leading security practices across all our products, services, and internal operations. Our security program encompasses:

Encryption

TLS 1.3 for data in transit and AES-256 for data at rest across all systems

Authentication

Multi-factor authentication (MFA) and JWT-based secure session management

Infrastructure

Enterprise-grade cloud hosting with automated failover and geographic redundancy

Monitoring

24/7 threat detection, real-time intrusion prevention, and automated alerting

2. Security Practices

Our comprehensive security framework includes the following practices implemented across all Royal Emerging products and client projects:

  • Secure Software Development Lifecycle (SSDLC): Security is integrated into every phase of our development process — from architecture design through code reviews, automated testing, and deployment.
  • Regular Penetration Testing: We conduct periodic penetration tests and vulnerability assessments on our SaaS products and critical infrastructure, performed by both internal security engineers and independent third-party auditors.
  • Dependency Management: All third-party libraries and packages are continuously monitored for known vulnerabilities using automated scanning tools with real-time alerting.
  • Access Control: Role-Based Access Control (RBAC) with the principle of least privilege is enforced across all internal systems and client-facing products. Admin access requires multi-factor authentication.
  • Data Backup & Recovery: Automated daily backups with encrypted off-site storage. Disaster recovery procedures are tested quarterly to ensure business continuity.
  • Employee Security Training: All team members undergo mandatory security awareness training, including phishing simulation exercises and secure coding practices workshops.

3. Vulnerability Reporting Program

We welcome responsible security researchers and ethical hackers to help us identify and resolve vulnerabilities in our systems. If you discover a potential security issue, please report it following these guidelines:

How to Report a Vulnerability

  1. 1Send an email to security@royalemerging.com with the subject line: “Security Vulnerability Report”
  2. 2Include a detailed description of the vulnerability, affected systems or URLs, and steps to reproduce the issue
  3. 3Attach proof-of-concept code, screenshots, or video recordings demonstrating the vulnerability (if available)
  4. 4Provide your contact information for follow-up communication and coordinate remediation timelines

4. Responsible Disclosure Guidelines

To protect our users and maintain the integrity of our systems, we ask security researchers to adhere to the following responsible disclosure principles:

✅ Do

  • • Report vulnerabilities promptly and responsibly
  • • Allow reasonable time (90 days) for remediation before public disclosure
  • • Test only against accounts and systems you own or have explicit authorization to test
  • • Minimize data access to what is necessary to demonstrate the vulnerability
  • • Communicate exclusively through designated security channels

❌ Do Not

  • • Access, modify, or delete data belonging to other users
  • • Exploit vulnerabilities beyond what is necessary for proof-of-concept
  • • Perform denial-of-service (DoS/DDoS) attacks
  • • Use social engineering or phishing against our staff or users
  • • Publicly disclose vulnerabilities before coordinated remediation

5. Incident Response Procedure

Royal Emerging maintains a structured incident response plan to address security events swiftly and effectively:

01

Detection & Triage

< 1 hour

Our monitoring systems detect anomalies in real-time. Alerts are immediately triaged by the security team to assess severity and scope.

02

Containment

< 4 hours

Affected systems are isolated to prevent further damage. Forensic evidence is preserved for investigation while maintaining service availability.

03

Investigation & Remediation

< 24 hours

Root cause analysis is conducted. Patches, configuration changes, or system updates are deployed to eliminate the vulnerability.

04

Notification

< 72 hours

Affected clients are notified with full transparency — including the nature of the incident, data affected, actions taken, and recommended steps.

05

Post-Incident Review

< 7 days

A comprehensive post-mortem is conducted. Lessons learned are documented and incorporated into our security practices to prevent recurrence.

6. Product-Specific Security

Our SaaS products, including RE Management (Retail ERP & Inventory System), implement the following product-level security measures:

  • Input Validation & Sanitization: All user inputs are validated and sanitized server-side to prevent SQL injection, XSS, and CSRF attacks.
  • Password Security: All passwords are hashed using bcrypt with salt rounds. Plaintext passwords are never stored or logged.
  • API Security: All API endpoints are authenticated via JWT tokens with configurable expiration policies. Rate limiting is enforced to prevent abuse.
  • Session Management: Secure session handling with automatic timeout, token rotation, and forced logout on password change or suspicious activity detection.
  • Audit Logging: All critical actions (login, data modification, permission changes) are logged with timestamps, user IDs, and IP addresses for full traceability.

7. Scope of This Policy

This security disclosure policy applies to all digital assets owned and operated by Royal Emerging, including:

AssetDomain / URLStatus
Corporate Websiteroyalemerging.comIn Scope
RE Management ERP*.vercel.app (demo instances)In Scope
Client ProjectsVarious client domainsOut of Scope
Third-Party ServicesAnalytics, CDN, payment gatewaysOut of Scope