Responsible Disclosure Policy

Prolarys CommV, trading as ScaleUP Security

Last updated:

Prolarys CommV and its affiliate ScaleUP Security Inc. ("ScaleUP Security", "we", "us" or "our") take the security of their systems — and of the clients we serve — seriously. As a cybersecurity and compliance company, we recognize the valuable role that independent security researchers and the wider community play in keeping systems safe. This Responsible Disclosure Policy explains how to report a security vulnerability to us, what you can expect from us in return, and the conditions under which we will consider your research to be authorized.

We encourage the responsible disclosure of security vulnerabilities through the process described below. We will not take, or support, legal action against anyone who discovers and reports a vulnerability in good faith and in accordance with this Policy.

SCOPE

This Policy applies to security vulnerabilities discovered in systems and services owned or operated by ScaleUP Security, including:

The following are out of scope:

GUIDELINES FOR RESEARCHERS

When investigating a potential vulnerability, we ask that you:

Please do not:

HOW TO REPORT A VULNERABILITY

Please send your report by email to hello@scaleupsec.com. To help us triage and resolve the issue quickly, please include as much of the following as you can:

Please submit reports in English, and encrypt any sensitive details where possible. We will provide a secure channel or encryption key on request.

WHAT YOU CAN EXPECT FROM US

When you submit a report in line with this Policy, we will make our best effort to:

  1. acknowledge receipt of your report within three (3) business days;
  2. validate the issue and keep you reasonably informed of our progress;
  3. work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity and risk;
  4. notify you when the issue has been resolved;
  5. publicly acknowledge your contribution, with your permission, once the issue is fixed.

SAFE HARBOR

ScaleUP Security considers security research and vulnerability disclosure conducted in good faith and in accordance with this Policy to be authorized conduct. We will not initiate or recommend legal action against you for accidental, good-faith violations of this Policy, and we will take steps to make it known that your actions were conducted in compliance with it.

This Policy does not grant you permission to act in any manner that is inconsistent with the law, or that would cause ScaleUP Security to be in breach of any of its legal or contractual obligations. It also does not authorize testing against systems or data belonging to third parties or our clients. If in doubt about whether a specific action is authorized, please contact us before proceeding.

If you are in Belgium, Belgian law offers additional legal protection to ethical hackers who meet the conditions set by the Centre for Cybersecurity Belgium (CCB), including reporting the vulnerability to the CCB. See ccb.belgium.be for the current conditions.

COMMONLY EXCLUDED FINDINGS

Unless you can demonstrate a realistic security impact, the following types of findings are generally considered low priority or out of scope:

RECOGNITION AND REWARDS

ScaleUP Security does not currently operate a paid bug-bounty program. We greatly value the contributions of the research community and are happy to acknowledge researchers who responsibly report valid vulnerabilities, where they wish to be recognized.

CONTACT

For any questions about this Policy, or to report a security vulnerability, please contact us at hello@scaleupsec.com.

We may update this Policy from time to time. The current version is published on our website, and any changes take effect when posted.