Skip to main content

Policy

Coordinated vulnerability disclosure

If you find a security issue in anything we publish, we want to hear it, and we will not take action against you for telling us.

How to report

Send it to security@assetshopenterprise.com. Include what you found, how to reproduce it, and what you think the impact is. Encrypted mail is welcome; the key is published beside this page.

What we commit to

StageCommitment
AcknowledgmentWithin 2 working days, from a person
TriageSeverity and a first assessment within 5 working days
Fix or planA remediation or a dated plan within 30 days
DisclosureCoordinated. We will agree timing with you and credit you unless you ask us not to

Safe harbor

Good-faith research that follows this policy is authorized. We will not pursue legal action, and we will say so in writing if you need it for your employer.

Out of scope

Denial of service, physical attacks, social engineering of our people, and findings against third-party services we do not operate. Automated scanner output without a demonstrated impact is not a report.

What is not claimed

No third-party penetration test has been performed and the platform is not certified for anything. This policy describes how we will handle a report, not an assurance that none exists to find.