Responsible Disclosure Policy
Prolarys CommV and its affiliate ScaleUP Security Inc. ("ScaleUP Security", "we", "us" or "our") take the security of their systems — and of the clients we serve — seriously. As a cybersecurity and compliance company, we recognize the valuable role that independent security researchers and the wider community play in keeping systems safe. This Responsible Disclosure Policy explains how to report a security vulnerability to us, what you can expect from us in return, and the conditions under which we will consider your research to be authorized.
We encourage the responsible disclosure of security vulnerabilities through the process described below. We will not take, or support, legal action against anyone who discovers and reports a vulnerability in good faith and in accordance with this Policy.
SCOPE
This Policy applies to security vulnerabilities discovered in systems and services owned or operated by ScaleUP Security, including:
- our public website at scaleupsec.com, and its related subdomains;
- internet-facing applications and services operated by ScaleUP Security and its affiliates.
The following are out of scope:
- third-party platforms, products or services that we use but do not operate or control (please report those to the relevant third party);
- our clients' systems or environments, unless you are acting under an explicit, written engagement with us that authorizes such testing;
- findings that require physical access to our premises, devices or personnel;
- social engineering (including phishing) of our staff, contractors or clients;
- denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks.
GUIDELINES FOR RESEARCHERS
When investigating a potential vulnerability, we ask that you:
- act in good faith and make every effort to avoid privacy violations, degradation of our services, and the destruction or alteration of data;
- only interact with accounts you own or for which you have the explicit permission of the account holder;
- use only the minimum level of access necessary to demonstrate a vulnerability, and do not attempt to pivot to other systems;
- stop testing and notify us immediately if you encounter any sensitive data, such as personal data, credentials, or proprietary information, and do not access, copy, store or disclose that data;
- give us a reasonable opportunity to investigate and remediate the issue before disclosing it publicly or to any third party.
Please do not:
- access, modify or delete data that does not belong to you;
- perform any action that could degrade, disrupt or damage our systems or the experience of other users;
- use automated scanners or tools in a manner that generates excessive traffic;
- attempt social engineering, phishing, or physical intrusion;
- demand payment or make threats in exchange for vulnerability information, which we do not consider good-faith research.
HOW TO REPORT A VULNERABILITY
Please send your report by email to hello@scaleupsec.com. To help us triage and resolve the issue quickly, please include as much of the following as you can:
- a clear description of the vulnerability and its potential impact;
- the affected URL, endpoint, system or asset;
- step-by-step instructions to reproduce the issue, including any proof-of-concept code, requests or screenshots;
- any tools, configurations or conditions required to reproduce it;
- your name or alias and a way to contact you, if you would like acknowledgement or follow-up.
Please submit reports in English, and encrypt any sensitive details where possible. We will provide a secure channel or encryption key on request.
WHAT YOU CAN EXPECT FROM US
When you submit a report in line with this Policy, we will make our best effort to:
- acknowledge receipt of your report within three (3) business days;
- validate the issue and keep you reasonably informed of our progress;
- work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity and risk;
- notify you when the issue has been resolved;
- publicly acknowledge your contribution, with your permission, once the issue is fixed.
SAFE HARBOR
ScaleUP Security considers security research and vulnerability disclosure conducted in good faith and in accordance with this Policy to be authorized conduct. We will not initiate or recommend legal action against you for accidental, good-faith violations of this Policy, and we will take steps to make it known that your actions were conducted in compliance with it.
This Policy does not grant you permission to act in any manner that is inconsistent with the law, or that would cause ScaleUP Security to be in breach of any of its legal or contractual obligations. It also does not authorize testing against systems or data belonging to third parties or our clients. If in doubt about whether a specific action is authorized, please contact us before proceeding.
If you are in Belgium, Belgian law offers additional legal protection to ethical hackers who meet the conditions set by the Centre for Cybersecurity Belgium (CCB), including reporting the vulnerability to the CCB. See ccb.belgium.be for the current conditions.
COMMONLY EXCLUDED FINDINGS
Unless you can demonstrate a realistic security impact, the following types of findings are generally considered low priority or out of scope:
- reports generated solely by automated tools or scanners, without a working proof of concept;
- missing security best-practice headers or cookie flags with no demonstrable exploit;
- SPF, DKIM or DMARC configuration suggestions, unless practically exploitable;
- clickjacking on pages with no sensitive actions, self-XSS, and logout or unauthenticated CSRF;
- software version disclosure or banner grabbing without an associated, exploitable vulnerability;
- the absence of rate limiting, where no concrete security impact is shown.
RECOGNITION AND REWARDS
ScaleUP Security does not currently operate a paid bug-bounty program. We greatly value the contributions of the research community and are happy to acknowledge researchers who responsibly report valid vulnerabilities, where they wish to be recognized.
CONTACT
For any questions about this Policy, or to report a security vulnerability, please contact us at hello@scaleupsec.com.
We may update this Policy from time to time. The current version is published on our website, and any changes take effect when posted.