Skip to main content

Vulnerability Disclosure

We appreciate the security research community’s efforts to improve our security.

Reporting

Email: [email protected] Include:
  • Detailed description
  • Steps to reproduce
  • Potential impact
  • Your contact info

Response Timeline

TimelineAction
24 hoursAcknowledgment
72 hoursInitial assessment
7 daysStatus update
90 daysCoordinated disclosure

Scope

In Scope:
  • ASG Gateway
  • ASG Console
  • Payment systems
  • Authentication
Out of Scope:
  • Third-party services
  • Social engineering
  • Physical security
  • DoS attacks

Safe Harbor

We will not pursue legal action against researchers who:
  • Report in good faith
  • Avoid privacy violations
  • Give reasonable response time
  • Don’t exploit beyond PoC

Recognition

Contributors may be featured in our Hall of Fame and eligible for bounties.