1. Owner and scope
Owner: Capalty LLC / MonthlyIQ. Security owner: Eric Zhivalyuk, Founder (security@monthlyiq.com). Effective September 27, 2026.
2. Purpose
MonthlyIQ identifies, evaluates and remediates security vulnerabilities affecting production assets, application dependencies, and workforce endpoints that can access sensitive systems.
3. Program
- Dependency and source-code vulnerability alerts are enabled where supported.
- Secret scanning is enabled for source repositories where supported.
- Automated database security scanning checks access policies and configuration.
- Internet-facing production assets are periodically scanned for known vulnerabilities and insecure configuration.
- Workforce computers with production access use current supported operating systems, automatic security updates, device lock and endpoint protection.
- End-of-life software is upgraded, removed, isolated or formally risk-accepted.
- Findings are triaged by severity, exploitability, exposure and data sensitivity.
4. Remediation targets
- Critical: as soon as practicable, target within 7 calendar days.
- High: within 30 calendar days.
- Medium: within 90 calendar days.
- Low: through normal maintenance based on risk.
- Missed targets are documented with reason, interim mitigation, owner and revised date.
5. Secure releases
Material production changes are reviewed and tested before deployment. Production errors must not expose secrets, credentials, access tokens, database details or unnecessary consumer financial information.
6. Review
Reviewed at least annually and after material incidents or architectural changes.
7. Contact us
Capalty LLC, doing business as MonthlyIQ (“MonthlyIQ,” “we,” “us,” or “our”).
- Privacy: privacy@monthlyiq.com
- Support: support@monthlyiq.com
- Security: security@monthlyiq.com
- Mail: 500 S. Australian Ave., Ste 600 #1072, West Palm Beach, FL 33480
MonthlyIQ is a product and trade name operated by Capalty LLC, a Florida limited liability company.
