RESPONSIBLE DISCLOSURE
Found something? Tell us.
We welcome good-faith security research. This page is the policy behind our security.txt.
How to report
Email info@vendorbenchmark.com with the subject line “Security report”.
- What you found
- The steps to reproduce it
- The URL or endpoint involved
- The impact you believe it has
A proof of concept helps; access to another customer’s data does not need to be proven beyond the first record.
What we commit to
- We acknowledge reports within 3 business days
- We keep you informed while we investigate, and tell you when the issue is fixed
- We do not run a paid bounty program today
- We credit researchers who want credit, and we say thank you properly
Safe harbor
We will not pursue legal action for research that stays within this policy.
- Act in good faith
- Access only what is needed to demonstrate the issue
- Do not read or modify other customers’ data beyond the minimum proof
- Do not degrade the service
- Give us reasonable time to fix the issue before any public disclosure
Out of scope
- Denial of service and volumetric testing
- Social engineering of our staff or customers
- Physical attacks and attacks on third-party services we use
- Reports from automated scanners without a demonstrated impact
Where to look first
The security overview describes the architecture. The isolation boundary is the crown jewel; if you find a way across it, we want to know the same day.
- Database-enforced tenant isolation
- Signed short-lived downloads
- Audit logging