Security & Anti-Impersonation Policy
Effective Date: 18th Aug, 2026
Last Updated: 18th Aug, 2026
Policy Owner: Graviron Aerospace, Inc.
1. Purpose
Graviron Aerospace, Inc. (“Graviron,” “we,” “our,” or “us”) is committed to protecting our employees, advisors, collaborators, customers, partners, suppliers, applicants, investors, and the information entrusted to us.
As Graviron operates in the aerospace sector and works with a growing network of employees, advisors, contractors, research collaborators, suppliers, partners, and other organizations, we recognize that our company, personnel, and relationships may be targeted by phishing, social engineering, impersonation, fraud, and other malicious activity.
This policy establishes how Graviron communicates about security-sensitive matters and provides guidance for recognizing and verifying communications that appear to originate from Graviron.
When in doubt, stop and verify through an independent, trusted channel before taking action.
2. Official Graviron Communications
Official Graviron communications may originate only from authorized company accounts, systems, or representatives.
Our official website is:
graviron.space
Company communications may be conducted through authorized Graviron email addresses and approved collaboration platforms.
However, the appearance of a company name, logo, employee name, photograph, email signature, LinkedIn profile, or other identifying information does not by itself establish that a communication is legitimate.
Attackers may impersonate employees, executives, recruiters, advisors, suppliers, or other individuals associated with an organization.
If a communication appears unusual or requests sensitive action, verify it independently using a trusted contact method.
This approach is consistent with guidance from NIST, which recommends verifying suspicious or urgent requests using known contact information rather than relying on contact details contained in the suspicious message itself.
3. Graviron Will Never Request Sensitive Credentials Through an Unverified Channel
Graviron will never unexpectedly request passwords, authentication codes, MFA codes, recovery codes, private cryptographic keys, or similar authentication credentials through email, SMS, social media, messaging applications, or other unofficial channels.
You should never provide such information in response to an unsolicited request claiming to originate from Graviron.
This includes requests for:
- Passwords
- One-time authentication codes
- MFA approval codes
- Recovery codes
- API keys
- Private keys
- Security tokens
- Authentication cookies or session information
- Personal account credentials
- Access to another person’s account
If someone claiming to represent Graviron requests any of the above, stop communicating through that channel and independently verify the request.
4. Financial and Payment Fraud
Graviron takes financial impersonation and payment fraud seriously.
A suspicious request may include instructions to:
- Purchase gift cards or prepaid cards
- Purchase cryptocurrency or digital assets
- Transfer money to an unfamiliar account
- Change banking or payment information
- Make an urgent payment
- Pay an invoice through an unusual method
- Purchase equipment or services outside normal procurement procedures
- Send payment credentials
- Change a supplier’s payment destination
- Circumvent normal approval procedures
- Keep a transaction secret from other authorized personnel
Urgency is not authorization.
Employees, contractors, suppliers, partners, and other representatives should independently verify unusual financial requests before taking action.
Northrop Grumman, for example, has publicly warned suppliers about fraudulent actors impersonating company personnel and making false procurement requests.
5. Recruitment and Hiring Fraud
Graviron is committed to protecting applicants and prospective employees from fraudulent recruitment activity.
A person claiming to represent Graviron may attempt to impersonate:
- A recruiter
- A hiring manager
- A founder or executive
- An employee
- An advisor
- A recruiting agency
- A third-party hiring partner
Graviron will not:
- Require applicants to purchase equipment, gift cards, cryptocurrency, or other products as a condition of employment.
- Request payment in exchange for an interview, offer, or employment opportunity.
- Ask applicants to transfer money on behalf of Graviron.
- Request passwords or MFA codes.
- Require applicants to deposit or cash a check and return a portion of the money.
- Ask applicants to purchase software or hardware from an unverified vendor as part of a recruitment process.
- Ask candidates to provide sensitive financial credentials through an unofficial channel.
Candidates should be particularly cautious of unsolicited job offers received through personal email accounts, messaging applications, social media, or other channels that do not correspond with the recruitment process established by Graviron.
If you receive a suspicious recruitment communication claiming to represent Graviron, verify it through an official Graviron channel before providing information or taking action.
6. Supplier, Procurement and Partner Fraud
Fraudulent actors may impersonate Graviron personnel when communicating with suppliers, manufacturers, research institutions, logistics providers, contractors, or other partners.
Examples include requests to:
- Purchase components or equipment
- Change shipping addresses
- Modify payment information
- Send confidential documents
- Provide quotations
- Execute contracts
- Share technical drawings
- Transfer intellectual property
- Expedite an unusual transaction
- Provide access to systems or repositories
- Send materials to an unfamiliar address
Partners should independently verify unusual requests, particularly requests involving money, sensitive information, technical materials, shipping destinations, credentials, or changes to established procedures.
For significant or unusual requests, use an established contact with Graviron rather than replying solely through the channel in which the request was received.
7. Executive and Employee Impersonation
Publicly available information about Graviron personnel may be used by malicious actors to create convincing impersonation attempts.
Potential impersonation methods include:
- Fake email addresses
- Look-alike domains
- Compromised accounts
- Fake LinkedIn profiles
- Fake social media accounts
- SMS messages
- Messaging applications
- Voice calls
- Video calls
- Deepfake or manipulated media
- Spoofed documents
- Fake signatures
- Copied company branding
A request should not be considered legitimate solely because it appears to come from a senior executive, founder, advisor, recruiter, or other recognizable individual.
When a request is unusual, independently verify the person’s identity using a previously established contact method.
8. Social Media and Public Profiles
Graviron recognizes that social media and professional networking platforms are valuable communication channels but can also be used for impersonation and social engineering.
The presence of a Graviron employee, advisor, partner, or executive on a social platform does not mean that every account using their name or photograph is legitimate.
Be cautious of:
- Newly created profiles
- Slightly altered names
- Look-alike accounts
- Unusual requests from existing contacts
- Requests to move conversations to unfamiliar platforms
- Requests for confidential information
- Requests for money or purchases
- Requests involving credentials or account access
When necessary, verify the person’s identity through an established company channel.
9. Confidential, Proprietary and Technical Information
Graviron personnel and external representatives may have access to confidential or proprietary information.
No individual should disclose confidential information solely because another person claims to be:
- A Graviron employee
- A founder or executive
- An investor
- A customer
- A supplier
- A government representative
- A research institution
- A journalist
- A recruiter
- A lawyer or professional service provider
Requests for sensitive information should be verified according to the person’s authorized role and the applicable confidentiality, NDA, IP, contractual, or other legal obligations.
Examples of information that may require additional verification include:
- Proprietary technical information
- Engineering documentation
- Design files
- Source code
- Research data
- Internal product information
- Manufacturing information
- Customer information
- Supplier information
- Financial information
- Contracts
- Credentials
- Internal communications
- Security information
- Non-public business plans
- Information subject to contractual, regulatory, export-control, or other legal restrictions
Public availability of some company information does not make all related information public.
10. Documents, Links and Attachments
Do not open unexpected attachments, execute unfamiliar files, install software, scan suspicious QR codes, or follow unusual links solely because they appear to originate from Graviron or a trusted third party.
Exercise additional caution when a message:
- Creates unusual urgency
- Requests a login
- Requests an unexpected document upload
- Requests installation of software
- Contains an unfamiliar attachment
- Uses a shortened or suspicious URL
- Directs you to a domain that does not match the expected organization
- Requests information that is inconsistent with the person’s role
When uncertain, independently navigate to the known official website or contact the organization using an established contact method rather than following the instructions in the suspicious message.
CISA identifies phishing, spearphishing, whaling, vishing and smishing as common forms of social engineering, including attacks that use convincing communications to obtain information or cause users to take malicious actions.
11. Verification of Sensitive Requests
For requests involving sensitive information, money, credentials, access, technical materials, contracts, or other significant actions, Graviron encourages a verify-before-act approach.
A recipient should consider:
> Who is making the request?
Is the person authorized to make this request?
> Is the request expected?
Does it make sense given the person’s role and the current business relationship?
> Is the communication channel normal?
Is the request arriving through an established company channel?
> Is there unusual urgency?
Does the sender insist that the request must be completed immediately?
> Does the request bypass normal procedures?
Is the sender asking you to avoid another employee, approval process, procurement process, or established communication channel?
> Can the request be independently verified?
Contact the person through a previously known phone number, email address, collaboration channel, or other trusted method.
12. Reporting Suspicious Activity
If you receive a suspicious communication claiming to represent Graviron, do not engage further than necessary to preserve evidence.
Where appropriate:
- Do not send money or sensitive information.
- Do not provide credentials or authentication codes.
- Do not click suspicious links or open unexpected attachments.
- Preserve the original message and relevant evidence.
- Report the communication to Graviron through an official security contact.
- If you believe an account or system has been compromised, immediately notify the appropriate Graviron contact.
Security Contact
> Contact Us through authorized channels
Website: graviron.space
If you are uncertain whether a communication genuinely originated from Graviron, contact us through information published on our official website rather than using contact information contained in the suspicious communication.
13. Suspected Account or Credential Compromise
If you believe that a Graviron-related account has been compromised:
- Stop using the potentially compromised account where practical.
- Do not approve unexpected MFA requests.
- Change affected credentials through the legitimate service.
- Revoke suspicious sessions or access tokens where possible.
- Notify Graviron through an established security channel.
- Preserve relevant evidence.
- Do not attempt to conceal or independently investigate an incident in a manner that could destroy evidence.
NIST’s current incident-response guidance emphasizes preparation, detection, response, recovery, communication, and incorporating lessons learned into cybersecurity risk management.
14. Third-Party and Partner Security
Security is a shared responsibility.
Graviron expects individuals and organizations accessing non-public Graviron information or systems to use reasonable security practices appropriate to their role and access.
Depending on the nature of a relationship, Graviron may require additional security controls, contractual obligations, confidentiality agreements, access restrictions, or incident-reporting requirements.
NIST’s Cybersecurity Framework specifically recognizes the importance of including relevant suppliers and third parties in cybersecurity incident planning and response.
15. Access Control
Access to Graviron systems and information should be limited according to legitimate business need.
Access may be:
- Granted based on role and responsibility
- Limited to the minimum information necessary
- Protected by authentication mechanisms
- Reviewed periodically
- Modified when responsibilities change
- Revoked when a person’s engagement ends
When an employee, advisor, contractor, collaborator, or other authorized individual leaves Graviron or no longer requires access, their access may be revoked as part of the company’s offboarding process.
16. Security Awareness
Graviron encourages employees, advisors, contractors, collaborators, and other authorized users to maintain awareness of common cybersecurity threats, including:
- Phishing
- Spearphishing
- Business email compromise
- Social engineering
- Credential theft
- Account takeover
- Executive impersonation
- Recruitment fraud
- Procurement fraud
- Payment fraud
- Malware
- Malicious links and attachments
- Fake websites
- Identity impersonation
- Deepfake and voice impersonation
- Insider threats
NIST’s Cybersecurity Framework specifically recommends security awareness training that includes recognizing social engineering, reporting suspicious activity, protecting credentials, and maintaining basic cyber hygiene.
17. Security Incidents
A security incident may include, among other things:
- Unauthorized access
- Suspected account compromise
- Credential theft
- Phishing
- Malware
- Data exposure
- Unauthorized disclosure
- Impersonation
- Fraudulent communications
- Unauthorized financial activity
- Loss or theft of devices containing company information
- Unauthorized access to technical or proprietary information
Graviron may take appropriate steps to contain, investigate, mitigate, document, and recover from security incidents.
Depending on the nature and impact of an incident, Graviron may also notify affected parties, service providers, law enforcement, regulators, customers, partners, or other relevant stakeholders where appropriate or legally required.
18. No Authorization Through Impersonation
No person may rely solely on an individual’s apparent identity, title, email signature, social-media profile, telephone number, or other representation as authorization to access information, systems, funds, facilities, or other resources.
Identity and authorization are separate questions.
Even if a communication genuinely comes from a known person, the requested action should still be appropriate to that person’s authority and the applicable company procedures.
19. Protecting Our Community
Graviron encourages employees, applicants, advisors, suppliers, partners, customers, investors, and members of the public to report suspected impersonation or fraudulent activity.
A report made in good faith will be treated seriously.
When reporting suspicious activity, please provide as much relevant information as reasonably possible, such as:
- The sender’s address or account
- Phone number
- Website or domain
- Screenshots
- Original message
- Attachments
- Requested action
- Date and time
- Any payment or information already provided
Do not intentionally forward malicious files or links to other individuals merely to warn them. When possible, provide the original message or evidence through the designated security reporting channel.
20. Important Notice
This policy is intended to help members of the Graviron community identify and respond to suspicious communications.
It does not mean that every communication originating from a Graviron domain or account is automatically safe, nor does it replace contractual, legal, regulatory, information-security, or incident-response requirements applicable to a particular relationship.
When something feels unusual:
Stop. Verify. Then act.
21. Policy Updates
Graviron may update this policy periodically as our organization, technology, operations, and threat environment evolve.
The latest version will be made available through the Graviron website.
Last Updated: 18th Aug, 2026
The Team, Graviron Aerospace, Inc.