SecurityPassport
Security

Security Disclosure Policy

Report potential vulnerabilities responsibly and review SecurityPassport expectations for vulnerability reporting, responsible disclosure, safe harbor, and research boundaries.

Disclosure
Clear reporting path for potential vulnerabilities.
Safe Harbor
Good-faith research expectations are documented.
Boundaries
Testing restrictions protect tenants and platform integrity.
Trust

Responsible disclosure connected to platform security and customer trust.

Vulnerability reporting
Good-faith research
Tenant protection
No disruption
Confidential handling
Security review
Legal

Security Disclosure Policy

Security Disclosure Policy

Last updated: June 3, 2026

  1. Introduction

SecurityPassport takes the security of our platform and customer data seriously.

We welcome responsible security research and encourage individuals to report potential vulnerabilities so they can be investigated and resolved.

  1. Reporting a Vulnerability

If you believe you have discovered a security vulnerability affecting SecurityPassport, please report it to:

hello@securitypassport.com

Please include:

description of the vulnerability

steps to reproduce the issue

affected systems or URLs

potential impact

proof-of-concept if available

We ask that vulnerability reports remain confidential until the issue has been investigated and resolved.

  1. Our Commitment

When a valid report is received, we aim to:

acknowledge the report within 3 business days

investigate the issue promptly

provide updates where appropriate

resolve confirmed vulnerabilities as quickly as possible

  1. Responsible Disclosure Guidelines

Researchers are expected to:

avoid accessing data belonging to other users

avoid modifying or deleting data

avoid service disruption (e.g., denial-of-service testing)

act in good faith and avoid privacy violations

Testing should be limited to your own accounts or data.

  1. Out of Scope

The following activities are generally considered out of scope:

social engineering attacks

physical attacks against infrastructure

denial-of-service attacks

automated vulnerability scanning without authorization

  1. Legal Safe Harbor

We will not pursue legal action against security researchers who:

follow this policy

report vulnerabilities responsibly

avoid violating privacy or disrupting services

  1. Recognition

We may publicly acknowledge responsible researchers who help improve the security of the platform.

Next step

Need to report a security issue?

Send responsible vulnerability reports to SecurityPassport with reproduction steps, affected systems, potential impact, and proof-of-concept details where available.