Responsible disclosure

How security researchers can report vulnerabilities to UpMonix in good faith.

Security contact

Report vulnerabilities to security@upmonix.com. Encrypt sensitive details if your report contains exploit information.

Scope

We welcome reports about security issues in UpMonix-owned web properties and the UpMonix application itself, including the customer dashboard, API, monitoring infrastructure and public tools hosted at upmonix.com.

Out of scope: third-party services, customer-hosted content, social engineering against staff, and issues in services we do not operate.

How to submit

Email security@upmonix.com with a clear description, steps to reproduce, impact assessment and any proof-of-concept you are comfortable sharing.

Information to include

  • Affected URL or component
  • Steps to reproduce
  • Expected vs actual behaviour
  • Severity assessment
  • Your contact details for follow-up

Acknowledgement

We aim to acknowledge reports within 1 business day. This is a target, not a contractual SLA.

Good-faith commitment

We will not pursue legal action against researchers who follow this policy and act in good faith.

Prohibited testing

You must not:

  • Access or alter customer data that is not your own
  • Perform denial-of-service testing
  • Send spam or unsolicited messages through our systems
  • Use social engineering against staff or customers
  • Disrupt production services beyond what is necessary to demonstrate a vulnerability
  • Download excessive data
  • Publicly disclose before coordinated remediation

Data handling

Do not include live customer data in reports. If you accidentally access customer data, stop immediately and report it.

Coordinated disclosure

Please allow reasonable time for us to investigate and remediate before public disclosure. We will work with you on an appropriate disclosure timeline.

UpMonix Business continuity monitoring — know before your customers do.