Security / responsible disclosure

Find something. Protect people first.

We welcome good-faith security research. This policy defines a safe, coordinated path that protects users, evidence and the researcher.

Program active · coordinated disclosure
SECURITY INTAKE POLICY / 1.0
01MINIMISEDATA
02PRESERVEEVIDENCE
03COORDINATEDISCLOSURE
security@ventex-connect.com
Private intake

Send the smallest useful report. Do not include production credentials, secret keys or personal message content. Encrypted intake can be coordinated on request.

Start a security report
IN / SCOPE

In scope

  • Public VENTEX Connect web application and API
  • Authentication, session and device-management controls
  • Authorisation boundaries and private attachment access
  • Cryptographic protocol implementation and key lifecycle
  • Product website endpoints operated by VENTEX
OUT / SCOPE

Out of scope

  • Social engineering, phishing and physical access
  • Denial of service, load tests, spam or automated account creation
  • Third-party services outside VENTEX operational control
  • Issues that require an obsolete browser or modified client without security impact
  • Reports containing only scanner output without a reproducible impact
RULES / GOOD FAITH

Research rules

  1. 01Use test accounts and the minimum number of requests required.
  2. 02Stop immediately if you encounter real user data or cross a tenant boundary.
  3. 03Do not persist, exfiltrate, modify or delete data.
  4. 04Do not degrade availability or interfere with other users.
  5. 05Keep the finding confidential until a coordinated disclosure date is agreed.
  6. 06Give VENTEX a reasonable opportunity to investigate and remediate.
PROCESS / TARGETS

Response targets

01

Acknowledgement

We confirm receipt and assign a reference when the report contains a reachable contact.

02

Initial triage

We assess scope, reproducibility and likely severity, then request missing evidence if necessary.

03

Progress update

For accepted findings, we share status while investigation or remediation is active.

04

Resolution and credit

We agree publication timing and researcher credit. No bounty is promised unless agreed in writing before work.

REPORT / EVIDENCE

A useful report includes

  • Affected URL, API route, component and observed version
  • Clear impact and who could be affected
  • Minimal step-by-step reproduction
  • Sanitised request/response evidence or a short proof of concept
  • Whether any real data was encountered and what you did next
  • Preferred name for credit, or a request to remain anonymous
SAFE HARBOR

Good-faith safe harbor

When research follows this policy, is lawful and is intended to improve security, VENTEX will not initiate legal action solely for that research. If a third party initiates action, we will make our good-faith assessment known where legally permitted.

This policy does not authorise violations of law, privacy, contracts you hold with third parties or access to data beyond what is strictly necessary to demonstrate the issue. Response times are targets, not guarantees.

Security improves when evidence reaches the people who can act on it.

Start a security report