Policy
Coordinated vulnerability disclosure
If you find a security issue in anything we publish, we want to hear it, and we will not take action against you for telling us.
How to report
Send it to security@assetshopenterprise.com. Include what you found, how to reproduce it, and what you think the impact is. Encrypted mail is welcome; the key is published beside this page.
What we commit to
| Stage | Commitment |
|---|---|
| Acknowledgment | Within 2 working days, from a person |
| Triage | Severity and a first assessment within 5 working days |
| Fix or plan | A remediation or a dated plan within 30 days |
| Disclosure | Coordinated. We will agree timing with you and credit you unless you ask us not to |
Safe harbor
Good-faith research that follows this policy is authorized. We will not pursue legal action, and we will say so in writing if you need it for your employer.
Out of scope
Denial of service, physical attacks, social engineering of our people, and findings against third-party services we do not operate. Automated scanner output without a demonstrated impact is not a report.
What is not claimed
No third-party penetration test has been performed and the platform is not certified for anything. This policy describes how we will handle a report, not an assurance that none exists to find.