Security Governance / Responsible Disclosure
Vulnerability Disclosure Policy
SUPENTIS values the security community. We encourage responsible vulnerability reporting for our platforms and public infrastructure under the safe harbor guidelines outlined below.
Safe Harbor Commitments
If you conduct security research in good faith and in compliance with this policy, SUPENTIS commits to:
- Not pursuing legal action or law enforcement escalation against good-faith researchers.
- Acknowledging receipt of vulnerability reports within 24 business hours.
- Providing regular updates regarding remediation timelines and validation.
Guidelines for Reporting
- Do not access, modify, or exfiltrate customer or institutional data.
- Do not execute Denial of Service (DoS/DDoS) attacks or automated brute-force spam.
- Allow reasonable time for remediation (standard 90-day window) prior to public disclosure.
Reporting Contact & PGP Key
Security Response Team
Email: security@supentis.com
PGP Fingerprint: 4B89 2F10 C932 7701 9A51 EA90 8F32 C210 SUP9 9002
