Loading...

FORCEFORE Safety and Security Policy

This version is not yet in force. It takes effect on November 7, 2026.

1. Scope and responsibilities

This policy explains common security practices and responsibilities across FORCEFORE services, including accounts, files, transactions, communications and systems. It supplements the terms, privacy policy and community rules. Application-specific arrangements belong to its Agreements or security instructions.

No measure guarantees that an incident can never occur. We adapt protection to risk and examine reports. Users help protect their access, but that responsibility does not remove FORCEFORE’s own legal duties, guarantees or responsibility for its conduct.

2. Credentials and account protection

Use a strong password different from passwords on other services. Never disclose it, including to someone claiming to be support. Passwords are stored as hashes. Where additional verification is available, protect its codes, temporary links and recovery methods too.

Protect the email, third-party account and telephone used for sign-in or recovery. Someone controlling a recovery method can compromise access. Sign out on shared devices and review available session or activity controls. A browser that remembers credentials also needs protection.

3. Phishing and misleading messages

Check domain, recipient and context before following a link, downloading a file or answering a payment request. Display names and logos can be copied. Urgent rewards, demands to pay to avoid punishment and requests for secret codes can indicate fraud.

Support does not ask you to reveal a password, one-time authentication code or complete card number in a conversation. Open https://forcefore.com/support yourself to verify a request. Do not send sensitive evidence to a social account that cannot be authenticated as an authorised contact.

4. Devices, software and purchases

Keep systems, browsers and applications updated and use appropriate distribution channels. Tools promising free paid benefits or unauthorised game modifications can steal information or compromise a device. Verify the origin and need for an unfamiliar tool before installing it as purported support advice.

Use the payment methods shown in official checkout or the relevant store. Check available parental and purchase controls on a child’s device. For an unrecognised charge, contact the competent payment provider promptly and support where useful. A legitimate payment remedy is not fraud in itself.

5. Data, files and access links

Internal access must be limited to people who need it for their duties. Files use dedicated infrastructure with protected storage and signed access links. Treat a link to a private document as confidential: sharing it can allow another person to read the file while that access remains valid.

Technical controls operate alongside access, verification and monitoring procedures. Do not place secrets in public screenshots, posts or unrelated attachments. The privacy policy describes purposes, recipients, retention and rights. Security is not blanket permission to keep all data indefinitely.

6. Detection and checks

Services can log connections, security events, errors, session references and abuse indicators to diagnose incidents and prevent harm. Access to logs must have a relevant purpose; they do not provide unrestricted access to users’ personal activities.

An automated alert can trigger verification, an additional control or a temporary restriction. Context should be considered before attributing misconduct where possible. Travel, a new device or a network fault does not alone prove compromise or abuse. You can request review of an apparently incorrect restriction.

7. Reporting vulnerabilities

Contact https://forcefore.com/support or contact@forcefore.com with the affected service, time, symptoms and minimum reproduction steps. If you encountered another person’s data, do not distribute it and keep copying to the minimum necessary. Request an appropriate channel before sending particularly sensitive evidence.

Do not extend a discovery into data extraction, account alteration, service interruption or testing on other users without authorisation. This policy does not authorise intrusive testing or establish a bounty programme or blanket immunity. A precise good-faith report helps correct a problem without increasing its impact.

8. Response and recovery

Depending on an incident, we may revoke sessions or tokens, restrict a function, correct software, restore access after verification and preserve necessary evidence. Protection can temporarily interrupt service. We seek proportionate measures and safe restoration without promising recovery of every record in every scenario.

If you suspect unauthorised access, secure your email and device, change affected secrets and use available session controls. Provide support with useful account references. Ownership checks must be proportionate; an account must not be handed to a third party on assertion alone.

9. Personal-data breaches

For a personal-data breach, we assess risk and applicable notification duties to authorities and affected people. Under the GDPR, notification to the authority is made where feasible within 72 hours of awareness unless risk is unlikely; a high risk can require informing affected people without undue delay.

Not every technical error is a personal-data breach, and not every breach requires the same public announcement. Information must be accurate, useful for protection and compatible with the investigation’s security. Social posts do not replace required individual notices or regulatory reporting.

10. Safety reports and changes

Threats, harassment, scams and privacy violations can be reported under the community rules. Support is not an emergency service; contact competent emergency services for immediate danger. Evidence may be shared with an authority where legally permitted or required and proportionate.

The version and effective date identify this policy. Material changes receive the relevant information and notice. For questions or accessibility difficulties with a protection mechanism, support is the common contact. Legal data, consumer and complaint rights remain applicable during incident handling.

Related documents