THIS POLICY IS NOT A GENERAL AUTHORISATION TO TEST OUR SYSTEMS. RESEARCHERS MUST REMAIN WITHIN THE EXPRESS SCOPE, AVOID HARM AND STOP IMMEDIATELY IF SENSITIVE DATA OR A MATERIAL RISK IS ENCOUNTERED.
Reporting channel
A suspected vulnerability should be reported to security@involvecsolutions.com with a concise description, affected URL or system, potential impact, reproduction steps, timestamps and supporting evidence.
Sensitive details should be transmitted by a secure method agreed with us. Unnecessary personal data must not be included.
Scope and authority
Testing is limited to accounts, systems and data owned by the researcher or expressly authorised in writing.
The existence of a public website, API endpoint or disclosure email address does not authorise bypassing authentication, accessing another user's data or testing third-party or Customer systems.
If scope or authority is uncertain, testing must stop until written clarification is obtained.
Permitted approach
- (a)
use the minimum activity and data necessary to confirm the suspected issue;
- (b)
use accounts and information the researcher is authorised to control;
- (c)
avoid affecting availability, integrity, confidentiality or another user's experience;
- (d)
report promptly and provide a reasonable opportunity for investigation and remediation; and
- (e)
maintain confidentiality until a coordinated disclosure is agreed.
Prohibited activity
- (a)
denial of service, load testing or degradation of availability;
- (b)
social engineering, phishing, bribery, threats or physical intrusion;
- (c)
credential stuffing, password spraying or automated high-volume scanning;
- (d)
accessing, altering, deleting, downloading or retaining another person's data;
- (e)
installing malware, creating persistence, pivoting to other systems or exfiltrating secrets;
- (f)
testing a provider, Customer system or third party without its written authority;
- (g)
public disclosure, sale, extortion or exploitation before coordinated resolution; and
- (h)
any activity prohibited by law.
Minimisation and stopping rules
Testing must stop when the vulnerability is sufficiently demonstrated, when personal or confidential data is encountered, when continued activity may cause harm or when we request a pause for investigation.
Data unintentionally obtained must not be copied further, shared or used. It must be securely deleted when we confirm that preservation is no longer necessary.
Our initial response
We aim to acknowledge a credible report, assess severity, reproduce the issue and identify an appropriate remediation route.
We may request additional technical detail, identity verification or confirmation of the researcher's actions. Acknowledgement does not constitute acceptance of liability or confirmation that the report is valid.
Remediation and communication
Remediation timing depends on severity, complexity, exploitation risk, testing requirements and third-party dependencies.
We will provide material progress information where appropriate, but may withhold details where disclosure would increase risk, reveal confidential information or compromise another investigation.
Good-faith treatment
Where a researcher acts in good faith, remains within this Policy, avoids harm, reports promptly and allows reasonable remediation time, we will not ordinarily pursue legal action solely for the authorised research activity.
This statement does not authorise breach of law, bind third parties or waive rights concerning extortion, data theft, privacy infringement, disruption, fraud or activity outside scope.
Coordinated disclosure
A report must not be publicly disclosed without our written agreement. Where disclosure is appropriate, the parties may agree a date, scope and wording after remediation and verification.
Recognition and rewards
We do not operate a standing bug-bounty programme and no payment, employment, contract or recognition is promised by submission of a report.
Any reward or public recognition is discretionary and may require identity, sanctions and eligibility checks.
Urgent incidents
An active compromise, exposed credential or immediate threat should be marked urgent and sent to security@involvecsolutions.com. General billing, access or support issues should be sent to support@involvecsolutions.com.