Responsible Disclosure Policy
Last updated: [DATE]
We take the security of Bastionize seriously and welcome reports from the security community. This
policy explains how to report a vulnerability in Bastionize's own systems and what
you can expect from us.
Reporting
Email security@bastionize.com with a clear description,
steps to reproduce, affected endpoints, and any proof-of-concept. Encrypt sensitive reports with our
PGP key ([link/fingerprint]) if you prefer. See also security.txt.
Our commitment ("safe harbour")
- We will acknowledge your report within [3 business days] and keep you updated on remediation.
- If you make a good-faith effort to comply with this policy, we will not pursue or support legal
action against you for your research.
- We will not share your details without consent, and we're happy to credit you once the issue is fixed.
Rules of engagement
- Only test accounts and data that belong to you; do not access, modify, or destroy others' data.
- No denial-of-service, spam, social engineering, or physical attacks.
- Do not run automated scanners against our production systems without prior written
authorization. Rate-limit manual testing and stop if you encounter sensitive data.
- Give us reasonable time to remediate before any public disclosure ([90 days] suggested).
In scope
bastionize.com and the Bastionize application. [List specific domains/APIs as your program matures.]
Out of scope
Third-party services, findings requiring unlikely user interaction, best-practice suggestions
without demonstrable impact, and volumetric/DoS issues. [Refine as needed.]
Thank you for helping keep Bastionize and its customers safe.