Responsible Disclosure Policy
[Syntropy AI Global LLC] values the work of independent security researchers in helping us maintain the security of our retail and enterprise software platforms. This policy sets out our reporting channel, rules of engagement, and safe harbor commitments.
1. How to Submit a Vulnerability Report (security@[yourdomain.com])
If you find a potential security bug, email security@[yourdomain.com] right away with clear steps to reproduce it.
Please send all suspected security vulnerability reports directly to security@[yourdomain.com]. To help our security engineering team triage and remediate the issue rapidly, please include:
- Affected domain, API endpoint, or client application version (Web, iOS, Android, Windows, macOS).
- Step-by-step instructions, HTTP request/response samples, or proof-of-concept code to reproduce the issue.
- Assessment of the potential security impact (e.g., cross-tenant access, XSS, authentication bypass).
- [PGP Key Fingerprint Placeholder: Insert PGP public key fingerprint for encrypted reports].
2. Scope & Good-Faith Rules of Engagement
Test only against your own test accounts, never access or modify real customer data, and never run denial-of-service or phishing attacks.
When conducting security research under this policy, you must adhere to the following rules:
- Do not access, view, modify, download, or delete data belonging to any third-party Syntropy customer or retail store.
- Do not execute Denial of Service (DoS/DDoS) attacks, automated brute-force credential stuffing, or physical intrusion against our offices or customer locations.
- Do not conduct social engineering or phishing attacks against Syntropy employees or customers.
- Allow our engineering team a reasonable remediation window (up to `[90 days]`) before disclosing the vulnerability publicly.
3. Our Response Timeline & Legal Safe Harbor
We acknowledge reports within [2 business days] and will not take legal action against researchers who follow these good-faith rules.
Response Commitment: We aim to acknowledge receipt of your report within `[2 business days]` and provide a triage validation update within `[5 business days]`.
Safe Harbor (Draft): When you conduct security research in good faith and strictly in accordance with this Responsible Disclosure Policy, [Syntropy AI Global LLC] considers your research authorized under applicable computer fraud statutes (including the CFAA) and will not initiate legal action against you.