Security
Responsible disclosure.
We spend our days finding weaknesses others cannot see. We take the same view of our own: if you have found a vulnerability in something we run, we want to hear about it, and we will treat you well for telling us.
How to reach us.
Send reports to [email protected]. Include enough for us to reproduce the issue: the affected URL or endpoint, the steps you took, what you observed, and your assessment of impact. Proof-of-concept detail is welcome; exploitation beyond what is needed to demonstrate the issue is not.
A machine-readable version of this policy lives at /.well-known/security.txt.
What is in bounds.
In scope: vigilocity.com and the publicly reachable services we operate under it. Out of scope: findings in third-party services we use but do not operate, social engineering of our staff or customers, physical attacks, denial of service or other volumetric testing, and reports generated by automated scanners without a demonstrated vulnerability.
If you are unsure whether something is in scope, ask first. We answer.
What to expect from us.
We acknowledge reports promptly, typically within three business days, keep you informed as we investigate and remediate, and credit you for the finding if you would like credit. We do not operate a paid bounty program.
Safe harbor: we will not pursue or support legal action against research conducted in good faith and within this policy. That means making a genuine effort to avoid privacy violations, data destruction, and service disruption, not accessing or retaining more data than a demonstration requires, and giving us reasonable time to remediate before any public disclosure. To the extent your good-faith research would otherwise violate an applicable anti-circumvention or computer misuse law, we authorize it within the limits of this policy.
