Last updated: January 2025
At Alertoscan, we take the security of our systems seriously. We value the security community and believe that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our users.
This policy describes how to report vulnerabilities to us, what we expect from you, and what you can expect from us.
This policy applies to all Alertoscan services and infrastructure, including:
The following are excluded from this policy:
Please report vulnerabilities through our contact form:
Report a Security Vulnerability
Select "Security Report" as the inquiry type.
To help us triage and respond quickly, please include:
When researching vulnerabilities, please:
When you report a vulnerability to us, we commit to:
| Action | Timeline |
|---|---|
| Initial acknowledgment | Within 3 business days |
| Severity assessment | Within 7 business days |
| Status update | At least every 14 days |
| Resolution target | 90 days (critical issues prioritized) |
Alertoscan will not pursue legal action against security researchers who:
We appreciate the security research community's efforts in helping keep our users safe. With your permission, we may:
If you have questions about this policy or need clarification before reporting, please contact us at contact@alertoscan.io.
This policy is based on industry best practices and guidelines from ISO/IEC 29147 and the NCSC Vulnerability Disclosure Toolkit.