
Responsible Disclosure Policy
Guidelines for reporting security vulnerabilities to INFOWATCH.
Purpose
INFOWATCH LLC is committed to maintaining the security, integrity, and availability of our systems, services, and information assets. We recognize the important role that security researchers, customers, and members of the cybersecurity community play in helping identify potential vulnerabilities. This Responsible Disclosure Policy provides guidelines for reporting security vulnerabilities and outlines our commitment to investigating and addressing valid security concerns in a timely and responsible manner.
Scope
This policy applies to:
- https://theinfowatch.com/
- INFOWATCH-owned websites
- Public-facing applications and systems owned and operated by INFOWATCH LLC
This policy does not authorize testing against:
- Client environments managed by INFOWATCH LLC
- Third-party systems
- Vendor platforms
- Systems not owned by INFOWATCH LLC
- Social engineering or phishing attacks against employees, contractors, or customers
Reporting a Vulnerability
Report vulnerabilities promptly to enquiries@theinfowatch.com, including:
- Detailed description
- Affected URL, system, or application
- Steps to reproduce
- Screenshots or supporting evidence if applicable
- Potential security impact
- Your name and contact information
Good Faith Security Research
Research is considered good faith when researchers:
- Act with the intention of improving security
- Avoid privacy violations
- Avoid service disruption
- Avoid unauthorized access to sensitive information
- Provide adequate time for remediation before public disclosure
- Comply with applicable laws
Guidelines for Researchers
Permitted Activities
- Identify and verify vulnerabilities responsibly
- Conduct limited testing necessary to confirm findings
- Submit findings directly to INFOWATCH LLC
- Protect information encountered during testing
Prohibited Activities
- Access, modify, or delete others' data
- Exfiltrate or copy confidential information
- Conduct denial-of-service (DoS) attacks
- Use automated tools that negatively affect availability
- Attempt privilege escalation beyond proof-of-concept
- Perform physical attacks
- Perform social engineering
- Install malware or backdoors
- Access client systems or data
Our Commitment
Upon receiving a report, we will:
- Acknowledge Receipt — within a reasonable period
- Investigate — our security team reviews and validates findings
- Remediate — confirmed vulnerabilities are prioritized by risk, impact, and exploitability
- Communicate — status updates where appropriate
Disclosure Guidelines
Researchers are requested to:
- Not publicly disclose until INFOWATCH has had reasonable opportunity to investigate and remediate
- Avoid publishing exploit code that could place users or systems at risk
- Coordinate disclosure with INFOWATCH whenever possible
INFOWATCH reserves the right to determine remediation timelines based on risk, complexity, and operational requirements.
Safe Harbor
INFOWATCH LLC will not initiate legal action against individuals who follow this policy, act in good faith, avoid causing harm to systems, users, or data, and comply with applicable laws. This applies only to activities fully complying with this policy; activities exceeding these guidelines may be subject to investigation and legal action.
Vulnerabilities of Interest
Web Application Security
- Authentication flaws
- Authorization bypasses
- Injection vulnerabilities
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Session management weaknesses
- API security issues
Infrastructure Security
- Misconfigurations
- Exposed administrative interfaces
- Weak encryption implementations
- Security control failures
Data Protection
- Unauthorized data exposure
- Sensitive information disclosure
- Privacy-related vulnerabilities
Cloud Security
- Improper access controls
- Storage misconfigurations
- Identity and access management weaknesses
Out of Scope
The following generally do not qualify:
- Missing security headers without demonstrable impact
- Clickjacking on non-sensitive pages
- Best-practice recommendations without security impact
- Self-XSS
- Social engineering attempts
- Physical security issues
- Reports involving outdated or unsupported browsers
- Automated scanner reports without validation
- Low-risk configuration observations without genuine security risk
Recognition
INFOWATCH values responsible security research and may, at its discretion and subject to applicable laws and business considerations, acknowledge researchers who submit valid and impactful vulnerability reports.
Confidentiality
All vulnerability reports are treated as confidential per our information security and privacy practices. Researchers should likewise protect sensitive information encountered during testing and disclosure.
Contact Information
- INFOWATCH LLC Responsible Disclosure Program
- Email: enquiries@theinfowatch.com
- General Inquiries: enquiries@theinfowatch.com
- Privacy Inquiries: enquiries@theinfowatch.com
- Website: https://theinfowatch.com/
