Responsible disclosure policy
We appreciate security research that helps keep our users and systems safe. If you believe you've found a vulnerability in an Iseer product, system, or service, please share it with us in a responsible manner so we can address it quickly.
Security First
We are committed to maintaining the highest security standards and working with the security community to protect our users.
Report vulnerabilities responsibly
Our promise
- We will acknowledge your report and begin triage within 3 business days.
- We will keep you informed of progress and fix timelines.
- We will not pursue legal action if you follow this policy in good faith (safe harbor).
We prioritize issues based on impact and exploitability. Indicative targets:
- Critical: acknowledge within 24h, aim to remediate within 7–14 days.
- High: acknowledge within 2 days, aim to remediate within 14–30 days.
- Medium/Low: scheduled remediation as part of regular releases.
Scope
In scope
Any publicly reachable Iseer-owned domain, subdomain, or product surface is in scope unless explicitly listed as out‑of‑scope below. Examples include:
- Web properties under
iseer.co(e.g.,iseer.co,auth.iseer.co). - Public APIs exposed by these domains.
Out of scope
- Denial of service (DoS/DDoS), volumetric attacks, or automated scanning that degrades service.
- Rate limiting, CAPTCHAs, or best‑practice headers in isolation without concrete exploitability.
- Clickjacking on pages without sensitive actions, open redirects without meaningful impact.
- Use of leaked, stolen, or previously compromised credentials.
Rules of engagement
- Do not access, modify, or exfiltrate data that is not your own. Use test accounts where possible.
- Avoid privacy violations and service disruption. No social engineering or physical attacks.
- Give us reasonable time to remediate before public disclosure.
Allowed during testing
- Testing on your own data and accounts.
- Non-destructive fuzzing of endpoints with moderate rates.
- Proofs of concept that minimize risk and exposure.
Prohibited activities
- Any action that degrades service (DoS/DDoS, brute-force at scale).
- Accessing, changing, or destroying data you do not own.
- Phishing, social engineering, physical intrusion.
How to report
Send a detailed report to disclosure@sentinel.iseer.co including:
- Vulnerability description, impact, and affected URLs/endpoints.
- Reliable reproduction steps (POC), any screenshots or logs, and your contact details.
- Optional: proposed remediation or references.
Quality checklist
- Unique and reproducible issue (not a duplicate).
- Clear impact statement and affected assets.
- Minimal steps to reproduce with expected vs actual behavior.
- Non-public data avoided or redacted.
Suggested report template
- Title: Concise summary
- Asset: e.g., app, domain, endpoint
- Severity: Critical / High / Medium / Low (w/ rationale)
- Impact: What an attacker can do
Safe harbor
If you comply with this policy and act in good faith, we will not pursue civil action or law enforcement investigation against you, and if a third party initiates legal action, we will make it known that your actions were conducted in good faith for security research. This safe harbor does not extend to actions that are illegal or harmful (e.g., exfiltrating personal data, ransom, extortion).
Recognition
We may acknowledge valid reports in our release notes or a hall of thanks. Monetary rewards are not guaranteed at this time.
- Public credit (with your consent) once a fix is released and verified.
- Preference for early access testing opportunities for consistent contributors.
Ready to Report a Vulnerability?
Help us maintain the highest security standards by reporting vulnerabilities responsibly.