Responsible Disclosure Policy

Last updated: [DATE]

We take the security of Bastionize seriously and welcome reports from the security community. This policy explains how to report a vulnerability in Bastionize's own systems and what you can expect from us.

Reporting

Email security@bastionize.com with a clear description, steps to reproduce, affected endpoints, and any proof-of-concept. Encrypt sensitive reports with our PGP key ([link/fingerprint]) if you prefer. See also security.txt.

Our commitment ("safe harbour")

Rules of engagement

In scope

bastionize.com and the Bastionize application. [List specific domains/APIs as your program matures.]

Out of scope

Third-party services, findings requiring unlikely user interaction, best-practice suggestions without demonstrable impact, and volumetric/DoS issues. [Refine as needed.]

Thank you for helping keep Bastionize and its customers safe.