// Security · Responsible Disclosure

Responsible Disclosure Policy

Threatstealth takes the security of its platform and customers' data seriously. We welcome reports from security researchers and the broader community.

72h Acknowledgement 90-Day Disclosure Safe Harbor Researcher Recognition

How to Report a Vulnerability

If you discover a security vulnerability in Threatstealth's platform, API, or web properties, please report it responsibly by emailing our security team directly. Include as much detail as possible to help us reproduce and verify the issue quickly.

Send vulnerability reports to:

security@threatstealth.com

Please include the following in your report:

Response Time Commitments

72h

Initial Acknowledgement

We will acknowledge receipt of your report within 72 hours and assign it a tracking reference number.

7d

Triage & Severity Assessment

We aim to complete initial triage and communicate our severity assessment within 7 business days.

30d

Remediation Target (Critical/High)

We target remediation of Critical and High severity findings within 30 days. We will keep you updated on progress.

90d

Coordinated Disclosure Deadline

We ask that you allow us 90 days from the date of your report before public disclosure. If we need more time, we will negotiate an extension with you directly.

Scope

In scope — we want to hear about vulnerabilities in:

threatstealth.com (main platform & API)

The marketing site, console, REST API (/api/*), authentication flow, multi-tenant data isolation, and security operations modules.

Login & Authentication (/login, /org-login, MFA)

Authentication bypass, session fixation, MFA weaknesses, token leakage, insecure cookie attributes.

API Security & Authorization

Missing authentication, broken object-level authorization, IDOR, SSRF, mass assignment, insecure direct object references.

Data Exposure & Injection

Cross-tenant data leakage, SQL/NoSQL injection, XSS, CSRF, stored vs. reflected injection flaws.

Out of scope — please do not report:

Social Engineering & Phishing

Attacks targeting Threatstealth employees, customers, or third parties via social engineering, pretexting, or phishing.

Physical Attacks

Physical access to Threatstealth offices, hardware, or infrastructure.

Denial of Service (DoS/DDoS)

Volumetric or resource-exhaustion attacks against Threatstealth infrastructure.

Third-Party Services

Vulnerabilities in third-party software or services that we use but do not control (e.g., cloud providers, CDNs, open-source libraries).

Low-Impact Issues

Missing security headers without demonstrated impact, SPF/DMARC configuration, clickjacking on pages without sensitive actions, cookie flags on non-sensitive cookies, or missing rate limits without demonstrated abuse.

Safe Harbor

Threatstealth considers security research conducted under this policy to be authorised and lawful. We will not initiate or recommend legal action against researchers who:

If you comply with the above guidelines, we commit to working with you rather than against you.

Researcher Recognition

We maintain a researcher recognition programme to acknowledge those who have made responsible disclosures. With your permission, we will acknowledge your contribution by name (or alias) and a brief description of the finding.

Threatstealth does not currently operate a paid bug bounty programme, but we deeply value the security research community and are committed to treating all reports with respect and transparency.

Encryption

If your report contains sensitive details, please contact our security team directly at security@threatstealth.com. Our security team's address is also listed in security.txt.