VULNERABILITY DISCLOSURE
We take the security of our own infrastructure seriously. If you have discovered a vulnerability in our systems, we want to hear from you.
Report a VulnerabilityOUR COMMITMENT
We will acknowledge your report within 48 hours.
We will investigate and validate your finding promptly and keep you informed of progress.
We will remediate critical vulnerabilities within 30 days and all findings within 90 days.
We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy.
We will credit you in our Hall of Fame if you consent to recognition.
PROCESS
Email security@theultrasecure.com with a clear description of the vulnerability, steps to reproduce, and potential impact. PGP encryption available on request.
We will acknowledge receipt of your report within 48 hours and assign a tracking reference number.
Our security team will triage your report, validate the finding, and assess severity using CVSS scoring.
We aim to remediate critical findings within 30 days and all findings within 90 days. We will keep you updated throughout.
Reporting Email
security@theultrasecure.com
Acknowledgement SLA
Within 48 hours
Remediation Target
90 days (30 days critical)
theultrasecure.com and all subdomains
Authentication and session management vulnerabilities
Cross-site scripting (XSS) and injection vulnerabilities
Insecure direct object references (IDOR)
Sensitive data exposure or information leakage
Security misconfigurations in web infrastructure
Broken access control vulnerabilities
Denial of service (DoS/DDoS) attacks of any kind
Physical security testing or social engineering of staff
Testing against client systems not owned by UltraSecure
Automated scanning without prior notification
Spam or phishing attacks against our staff
Vulnerabilities in third-party services beyond our control
Issues requiring physical access to devices
If you conduct vulnerability research in good faith, comply with this policy, and report findings through proper channels, UltraSecure will not pursue legal action against you. We consider responsible security research to be a valuable contribution to the security community.
Safe harbor applies provided you do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability, do not perform denial of service attacks, and do not disclose findings publicly before we have had a reasonable opportunity to remediate.
Researchers who have responsibly disclosed vulnerabilities to us
Be the First
No submissions yet. Found something? Email security@theultrasecure.com