Coordinated Vulnerability Disclosure
Sectricity BV
Scope
This policy applies to security vulnerabilities in:
Rules of Engagement
When conducting security research, you must:
- Act in good faith and avoid actions that could harm Sectricity, its customers, or its services
- Not access, modify, or delete data belonging to others
- Not disrupt or degrade the availability of our services
- Not exploit vulnerabilities beyond what is necessary to demonstrate the issue
- Not use automated scanning tools excessively or in a manner that impacts service performance
- Respect the privacy and data of our users at all times
- Comply with all applicable laws and regulations
Reporting Guidelines
To report a security vulnerability, please send an email to: security@sectricity.com
Please encrypt sensitive reports using our PGP key, available upon request.
Safe Harbor
Sectricity BV considers security research conducted in accordance with this policy to be:
- Authorized with respect to any applicable anti-hacking laws
- Exempt from restrictions in our Terms of Service that would interfere with conducting security research
- Lawful, helpful to the overall security of the internet, and conducted in good faith
We will not pursue legal action against researchers who discover and report vulnerabilities in accordance with this policy. If legal action is initiated by a third party against you for activities conducted in compliance with this policy, we will take reasonable steps to make it known that your actions were conducted in accordance with this policy.
Response & Timeline
When you submit a vulnerability report, you can expect:
- Acknowledgment of your report within 3 business days
- Regular updates on the status of your report
- An estimated timeline for remediation where applicable
- Notification when the vulnerability has been resolved
We ask that you keep the details of any vulnerability confidential until we have had a reasonable opportunity to investigate and address the issue.
Contact
For any questions regarding this policy or to report a security vulnerability: security@sectricity.com