1. Purpose
Volentas LLC ("Volentas," "we," "us," or "our") is committed to the security of its systems and the information entrusted to it. This Vulnerability Disclosure Policy (this "Policy") sets out the terms under which security researchers and members of the public ("you") may conduct good-faith security research on the systems identified in Section 2 and report vulnerabilities to us, the conduct we require of you, and the commitments we make in return. This Policy does not establish a bug bounty program, and no compensation is offered or implied for any report.
2. Scope
This Policy applies to the website located at volentas.com and its subdomains, the application programming interfaces and interactive features served from them, and the electronic mail infrastructure that sends messages from the volentas.com domain (collectively, the "Systems").
The following are outside the scope of this Policy:
- Systems, services, and infrastructure owned or operated by third parties, including service providers on which the Systems depend. Vulnerabilities in such systems must be reported to the responsible party;
- Findings generated solely by automated scanning tools that are not accompanied by a demonstrated, reproducible security impact;
- Denial-of-service testing, volumetric or resource-exhaustion testing, and any activity that degrades the availability of the Systems;
- Social engineering, phishing, or physical attacks directed at Volentas personnel, clients, or facilities; and
- Reports concerning the configuration of email authentication records, security headers, or software version disclosure that do not demonstrate an exploitable condition.
3. Authorization and Safe Harbor
Security research conducted in accordance with this Policy is authorized by Volentas. With respect to such research, Volentas (a) will not initiate or support civil or criminal legal action against you under anti-hacking laws, including the Computer Fraud and Abuse Act and analogous state statutes, or under anti-circumvention laws, including the Digital Millennium Copyright Act, for accidental or good-faith violations of this Policy; (b) waives, on a limited basis and solely to the extent necessary to permit research consistent with this Policy, any restriction in the terms governing use of the Systems that would otherwise prohibit such research; and (c) will, if a third party initiates legal action against you in connection with research conducted in compliance with this Policy, take reasonable steps to make known that your activities were authorized.
This authorization extends only to claims within the control of Volentas. It does not bind third parties, does not authorize any activity that violates applicable law, and does not extend to activity outside the scope described in Section 2 or in breach of Section 4. You remain responsible for compliance with all applicable laws. If you are uncertain whether a proposed activity is consistent with this Policy, submit an inquiry through the channel identified in Section 5 before proceeding.
4. Rules of Engagement
In conducting research and reporting under this Policy, you shall:
- Comply with this Policy and all applicable laws; in the event of any conflict between this Policy and other terms governing the Systems, this Policy governs with respect to security research;
- Report any vulnerability promptly after discovery, and refrain from public disclosure until Volentas has had a reasonable opportunity to remediate, which shall be not less than ninety (90) days from the date of your report unless otherwise agreed in writing;
- Refrain from accessing, modifying, deleting, or retaining data that does not belong to you beyond the minimum necessary to demonstrate a vulnerability, and cease testing and report immediately upon encountering personal information, confidential information, or credentials;
- Refrain from any action that disrupts the Systems, degrades their availability, or affects the experience of other users;
- Interact only with accounts and data that you own or are expressly authorized to use;
- Communicate regarding vulnerabilities solely through the channel identified in Section 5 and treat the contents of your report as confidential until remediation; and
- Refrain from conditioning disclosure or remediation assistance on the payment of money or other consideration.
Conduct inconsistent with this Section is outside the authorization granted in Section 3.
5. Reporting
Reports shall be submitted by electronic mail to
info@volentas.com. A report should
identify the affected System, describe the vulnerability and its potential impact,
and include the steps necessary to reproduce it, together with any supporting
material. You may report anonymously; however, we cannot provide status updates or
request clarification where no means of contact is provided. A machine-readable
statement of this reporting channel is published at
/.well-known/security.txt.
6. Our Commitments
With respect to reports submitted in accordance with this Policy, Volentas will:
- Acknowledge receipt within three (3) business days;
- Evaluate the report and communicate our determination of validity and severity within a reasonable time;
- Keep you reasonably informed of the status of remediation of a confirmed vulnerability;
- Remediate confirmed vulnerabilities as promptly as practicable in light of severity and operational constraints; and
- Upon request, and where the vulnerability is confirmed, acknowledge your contribution publicly, subject to your consent.
7. Personal Information
Personal information that you provide in connection with a report, including your name and contact details, is used solely to communicate with you regarding the report and to administer this Policy, and is handled in accordance with our Privacy Policy. We will not disclose your identity in connection with a report without your consent, except as required by law.
8. Reservation of Rights; Modification
Nothing in this Policy constitutes a waiver of any right or remedy of Volentas with respect to conduct outside the scope of this Policy. Volentas reserves the right to modify or withdraw this Policy at any time by posting a revised version on the Site; research commenced in good faith under a prior version remains authorized for a reasonable period sufficient to complete a report in progress.