
Security Policy and Responsible Disclosure
1. Security principles
- Verified identities only. Every account belongs to a named person at a verified organisation. See the Membership & Registration Policy.
- Least privilege. Each member, custodian and system component has only the access its role requires.
- Defence in depth. Independent layers of protection mean that no single control is relied on alone.
- Integrity of statistics. Official data is protected against alteration from the moment it is retrieved to the moment it is published.
2. Account protection
- Every member and custodian account is protected by device-based multi-factor authentication.
- Member accounts have no passwords, so there are none to phish, reuse or reset.
- Account recovery is never self-service. A custodian performs it only after verifying identity independently with the member's organisation.
- Sessions are protected against hijacking and cross-site attacks. They expire after inactivity, and custodians can end them immediately.
- Members are notified of security-relevant events on their account.
3. Protection against automated attack and abuse
The Service continuously defends against the following, restricting access progressively and automatically when abuse is detected:
- credential guessing and brute-force attempts;
- automated and bulk registration;
- scripted scraping;
- replay of intercepted codes;
- other forms of automated abuse.
Legitimate members are not affected in normal use.
4. Protection of data
- All connections to the Service are encrypted.
- Sensitive information, including authentication data and third-party credentials, is encrypted when stored.
- Only the minimum personal data needed for verification, security and account administration is collected. It is retained only for the periods in the Privacy Notice.
- Premium content, as it is released, is delivered only to entitled accounts and is traceable to the account that received it.
5. Operational security
- The Service runs in a hardened, access-controlled hosting environment with layered administrative safeguards.
- Custodial and administrative actions are recorded in a custodial audit trail and reviewed.
- Configuration, credentials and application code are protected from public access.
- Access rights and credentials are reviewed and rotated regularly, and immediately when roles change.
6. Incident response
If a security incident occurs, we will:
- contain it;
- investigate it;
- restore secure service.
Where required, we notify affected members and the relevant supervisory authorities within statutory deadlines. Affected sources or content may be withheld while integrity is confirmed.
7. What we ask of members
- Keep your authenticator device locked and under your control.
- Never share your codes. Eurabelt will never ask for them.
- Report a lost device, suspicious email or unexpected sign-in notice immediately.
- Tell us when a colleague leaves your organisation.
- Treat emails claiming to be from Eurabelt with caution unless they come from stats@eurabeltfuels.com and link to stats.eurabeltfuels.com.
8. Reporting a vulnerability
If you believe you have found a security vulnerability, email security@eurabeltfuels.eu. Please include:
- a description of the issue;
- the steps to reproduce it;
- the potential impact.
We will acknowledge your report within 5 working days and keep you informed until it is resolved.
9. Rules for good-faith research
- Test only against accounts you own or have explicit permission to test.
- Do not access, modify or retain other users' data.
- Do not degrade the Service. This rules out denial-of-service testing, automated high-volume scanning and social engineering of staff or members.
- Give us reasonable time to remediate before any disclosure.
We will not pursue action against researchers who act in good faith and within these rules.
10. Confidentiality of security measures
To protect members and the integrity of official data, Eurabelt does not publish technical details of its security controls, infrastructure or monitoring. Verified Sovereign/Enterprise members may request further assurance information under a confidentiality agreement.
Issued under the seal of the Eurabelt Custodial Order · Unity · Secrecy · Custodianship
