Responsible vulnerability disclosure
Certi360 website, https://certi360.com
We welcome responsible reports of security issues affecting this website and the services available on it. This document explains what we expect from researchers and how to contact us.
How to report a vulnerability
Send a detailed email to security@certi360.com. When you can, include:
- a description of the issue and its potential impact;
- the steps to reproduce the finding;
- the approximate date and time of your tests;
- a way to reach you for technical follow-up.
You may encrypt your message with the public PGP key published at https://certi360.com/.well-known/pgp-key.txt (referenced from security.txt).
What we ask
- Act in good faith: tell us about the issue without harming users or the service.
- Do not disrupt availability: avoid load testing, denial-of-service attempts, and any action that could degrade or interrupt the service.
- Respect other people's privacy: do not access accounts that are not yours. Do not view, copy or keep personal information beyond what is strictly needed to demonstrate the issue.
- Do not go further than necessary: limit your actions to what is needed to show that the issue exists and how serious it is.
- Keep the report confidential: do not disclose the vulnerability publicly until a reasonable fix has been deployed, unless we agree otherwise.
Scope
This policy covers the certi360.com website and the services published on it. It does not authorize testing of our customers' systems, or of environments we assess under an engagement.
Exposia publishes its own file: https://app.exposia.ca/.well-known/security.txt. The contact remains security@certi360.com.
Remediation window
We aim to acknowledge receipt within a reasonable time and to treat serious reports as a priority. Please allow a reasonable period (often about 90 days, depending on complexity) before any public disclosure, unless a legal duty or an imminent risk calls for faster communication.
After the report
Responsible reports are appreciated. When the circumstances allow it, we may offer a public acknowledgment. See the Acknowledgments page. No payment is guaranteed merely for disclosing a vulnerability. This document does not promise a formal bug bounty program.