UltraSecure

VULNERABILITY DISCLOSURE

Responsible Disclosure Policy

We take the security of our own infrastructure seriously. If you have discovered a vulnerability in our systems, we want to hear from you.

Report a Vulnerability

OUR COMMITMENT

What You Can Expect from Us

We will acknowledge your report within 48 hours.

We will investigate and validate your finding promptly and keep you informed of progress.

We will remediate critical vulnerabilities within 30 days and all findings within 90 days.

We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy.

We will credit you in our Hall of Fame if you consent to recognition.

PROCESS

How to Report

01

Submit Report

Email security@theultrasecure.com with a clear description of the vulnerability, steps to reproduce, and potential impact. PGP encryption available on request.

02

Acknowledgement

We will acknowledge receipt of your report within 48 hours and assign a tracking reference number.

03

Triage & Validation

Our security team will triage your report, validate the finding, and assess severity using CVSS scoring.

04

Remediation

We aim to remediate critical findings within 30 days and all findings within 90 days. We will keep you updated throughout.

Reporting Email

security@theultrasecure.com

Acknowledgement SLA

Within 48 hours

Remediation Target

90 days (30 days critical)

In Scope

theultrasecure.com and all subdomains

Authentication and session management vulnerabilities

Cross-site scripting (XSS) and injection vulnerabilities

Insecure direct object references (IDOR)

Sensitive data exposure or information leakage

Security misconfigurations in web infrastructure

Broken access control vulnerabilities

Out of Scope

Denial of service (DoS/DDoS) attacks of any kind

Physical security testing or social engineering of staff

Testing against client systems not owned by UltraSecure

Automated scanning without prior notification

Spam or phishing attacks against our staff

Vulnerabilities in third-party services beyond our control

Issues requiring physical access to devices

Safe Harbor

If you conduct vulnerability research in good faith, comply with this policy, and report findings through proper channels, UltraSecure will not pursue legal action against you. We consider responsible security research to be a valuable contribution to the security community.

Safe harbor applies provided you do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability, do not perform denial of service attacks, and do not disclose findings publicly before we have had a reasonable opportunity to remediate.

Hall of Fame

Researchers who have responsibly disclosed vulnerabilities to us

Be the First

No submissions yet. Found something? Email security@theultrasecure.com