Vulnerability Disclosure Policy
At surfaice.pro, we take the security of our systems and our customers' data seriously. We value the work of security researchers and believe that a responsible disclosure program is critical to building a secure product.
If you believe you have found a security vulnerability in our platform, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the issue.
1. Scope
The following properties are in-scope for this program:
- surfaice.pro
- agent.surfaice.pro
- Any official surfaice.pro APIs or mobile applications.
Out of Scope
The following activities and vulnerability types are strictly excluded:
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
- Social engineering (e.g., phishing, vishing) of surfaice.pro employees or contractors.
- Physical attacks against surfaice.pro offices or data centers.
- Vulnerabilities in third-party integrations (unless they reveal a flaw in our handling of those integrations).
- UI/UX "bugs" that do not have a security impact.
2. Guidelines for Researchers
To encourage responsible disclosure, we ask that you:
- Do no harm: Avoid activities that could cause data loss, service disruption, or degradation of the experience for other users.
- Respect Privacy: Do not attempt to access, modify, or delete data belonging to other users. If you accidentally encounter personal data, stop and report it immediately.
- Provide Details: Include clear, reproducible steps (POC) so our engineering team can verify the issue.
- Give us time: Please allow us a reasonable amount of time to remediate the issue before you share any details publicly.
3. How to Report
Please send your findings to our security team via email:
Email: dev@surfaice.pro
Subject: Security Vulnerability Report: [Brief Description]
What to include in your report:
- Description of the vulnerability.
- The exact URL or endpoint where the issue was found.
- Step-by-step instructions to reproduce the issue.
- Screenshots or video proof (if applicable).
- Potential impact of the vulnerability.
4. Our Commitment
If you follow these guidelines, surfaice.pro commits to:
- Acknowledging receipt of your report within 3–5 business days.
- Keeping you informed of our progress as we investigate and remediate.
- Recognizing your contribution to our security (with your permission).
5. Safe Harbor
surfaice.pro will not initiate legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We consider reports that follow these guidelines to be "authorized" conduct under relevant computer crime laws.
