Responsible disclosure
How security researchers can report vulnerabilities to UpMonix in good faith.
Security contact
Report vulnerabilities to security@upmonix.com. Encrypt sensitive details if your report contains exploit information.
Scope
We welcome reports about security issues in UpMonix-owned web properties and the UpMonix application itself, including the customer dashboard, API, monitoring infrastructure and public tools hosted at upmonix.com.
Out of scope: third-party services, customer-hosted content, social engineering against staff, and issues in services we do not operate.
How to submit
Email security@upmonix.com with a clear description, steps to reproduce, impact assessment and any proof-of-concept you are comfortable sharing.
Information to include
- Affected URL or component
- Steps to reproduce
- Expected vs actual behaviour
- Severity assessment
- Your contact details for follow-up
Acknowledgement
We aim to acknowledge reports within 1 business day. This is a target, not a contractual SLA.
Good-faith commitment
We will not pursue legal action against researchers who follow this policy and act in good faith.
Prohibited testing
You must not:
- Access or alter customer data that is not your own
- Perform denial-of-service testing
- Send spam or unsolicited messages through our systems
- Use social engineering against staff or customers
- Disrupt production services beyond what is necessary to demonstrate a vulnerability
- Download excessive data
- Publicly disclose before coordinated remediation
Data handling
Do not include live customer data in reports. If you accidentally access customer data, stop immediately and report it.
Coordinated disclosure
Please allow reasonable time for us to investigate and remediate before public disclosure. We will work with you on an appropriate disclosure timeline.