Applications in Scope
We are interested in identifying and addressing critical vulnerabilities in our infrastructure. Specifically, we focus on issues that could substantially impact the confidentiality, integrity, or availability of user data.
While we welcome all reports, not every finding will qualify for a reward. The decision to offer a reward will be at the discretion of the security team, based on the severity and impact of the reported vulnerability.
Important:
- Avoid Denial-of-Service (DoS) attacks, spam, or any activity that could disrupt our systems or degrade service availability.
- Refrain from using tools that generate excessive traffic during testing.
Eligibility and Responsible Disclosure
To ensure the security and privacy of our users, please adhere to the following guidelines:
- Report the Vulnerability: Share the technical details with us, including the exact domain and steps to reproduce the issue.
- Avoid Automated Scanning Tools: Do not spam our applications with automated vulnerability scanners.
- Do Not Make Public Disclosures: Give us adequate time to respond and address the issue before discussing it publicly.
- Do Not Modify User Data: You must not alter, save, transfer, or interact with data that does not belong to you.
- Respect Privacy: Avoid violating privacy rights, destroying data, or disrupting our services.
- Follow Legal and Ethical Guidelines: Testing must comply with applicable laws and must not intentionally disrupt other users or systems.
Timelines for Reporting and Resolution
We classify each verified vulnerability by severity, using CVSS v3.1 and our own assessment of its business impact:
| Severity | CVSS score | Example impact |
|---|---|---|
| Critical | 9.0–10.0 | Remote code execution, privilege escalation, unauthenticated data exfiltration |
| High | 7.0–8.9 | Authentication bypass, injection vulnerabilities, exposure of sensitive data |
| Medium | 4.0–6.9 | Information disclosure, privilege abuse, limited exploitability |
| Low | Below 4.0 | Minor misconfigurations or informational findings |
The severity sets how quickly we respond:
| Severity | Acknowledgment | Containment / Mitigation | Full Remediation | Verification & Closure |
|---|---|---|---|---|
| Critical | Within 1 business day | Within 1 business day | Within 3 days | Within 7 days |
| High | Within 2 business days | Within 3 business days | Within 7 days | Within 10 days |
| Medium | Within 5 business days | Within 10 business days | Within 30 days | Within 45 days |
| Low | Within 10 business days | As scheduled | Within 90 days | Within 120 days |
We will confirm receipt of your report within the acknowledgment time for its severity, and may request additional details if necessary. The other times count from that acknowledgment. If a full fix cannot be completed in time, we apply a temporary mitigation until it is.
Once the issue is resolved:
- Reward Decision:
- Timeline: Within 15 business days after resolution.
- If applicable, we will inform you of your eligibility for a reward. Reward decisions are based on the severity and impact of the vulnerability.
- Public Disclosure (Optional):
- Timeline: After mutual agreement or post-resolution (at least 90 days).
- Public disclosure can only occur after we provide explicit approval and after the issue is resolved.
Out-of-Scope Vulnerabilities
The following reports are out of scope:
- Weak password policies or lack of email/account verification.
- Reports from automated tools without clear analysis.
- Spam-related vulnerabilities or excessive email rates.
- Issues affecting outdated browsers or platforms no longer supported by their vendors.
- Well known exploits
How to Report Vulnerabilities to Us
When reporting a vulnerability:
- Include the exact domain and detailed reproduction steps.
- Clearly outline the potential impact of the vulnerability.
Contact Email: security@anafore.com
Our security team is committed to maintaining open communication and resolving issues promptly. Thank you for helping us improve the safety and reliability of our systems.