How to Report a Vulnerability
If you discover a security vulnerability in Threatstealth's platform, API, or web properties, please report it responsibly by emailing our security team directly. Include as much detail as possible to help us reproduce and verify the issue quickly.
Send vulnerability reports to:
security@threatstealth.comPlease include the following in your report:
- A clear description of the vulnerability and its potential impact
- The URL, endpoint, or component affected
- Step-by-step reproduction instructions
- Proof-of-concept (screenshots, HTTP request/response, video) if available
- Your suggested severity (Critical / High / Medium / Low)
Response Time Commitments
Initial Acknowledgement
We will acknowledge receipt of your report within 72 hours and assign it a tracking reference number.
Triage & Severity Assessment
We aim to complete initial triage and communicate our severity assessment within 7 business days.
Remediation Target (Critical/High)
We target remediation of Critical and High severity findings within 30 days. We will keep you updated on progress.
Coordinated Disclosure Deadline
We ask that you allow us 90 days from the date of your report before public disclosure. If we need more time, we will negotiate an extension with you directly.
Scope
In scope — we want to hear about vulnerabilities in:
threatstealth.com (main platform & API)
The marketing site, console, REST API (/api/*), authentication flow, multi-tenant data isolation, and security operations modules.
Login & Authentication (/login, /org-login, MFA)
Authentication bypass, session fixation, MFA weaknesses, token leakage, insecure cookie attributes.
API Security & Authorization
Missing authentication, broken object-level authorization, IDOR, SSRF, mass assignment, insecure direct object references.
Data Exposure & Injection
Cross-tenant data leakage, SQL/NoSQL injection, XSS, CSRF, stored vs. reflected injection flaws.
Out of scope — please do not report:
Social Engineering & Phishing
Attacks targeting Threatstealth employees, customers, or third parties via social engineering, pretexting, or phishing.
Physical Attacks
Physical access to Threatstealth offices, hardware, or infrastructure.
Denial of Service (DoS/DDoS)
Volumetric or resource-exhaustion attacks against Threatstealth infrastructure.
Third-Party Services
Vulnerabilities in third-party software or services that we use but do not control (e.g., cloud providers, CDNs, open-source libraries).
Low-Impact Issues
Missing security headers without demonstrated impact, SPF/DMARC configuration, clickjacking on pages without sensitive actions, cookie flags on non-sensitive cookies, or missing rate limits without demonstrated abuse.
Safe Harbor
Threatstealth considers security research conducted under this policy to be authorised and lawful. We will not initiate or recommend legal action against researchers who:
- Report vulnerabilities in good faith through this responsible disclosure process
- Do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability
- Do not disrupt Threatstealth services or degrade user experience
- Do not publicly disclose vulnerabilities before the 90-day coordinated disclosure deadline expires
- Do not violate any applicable laws beyond what is strictly necessary to test in-scope systems
If you comply with the above guidelines, we commit to working with you rather than against you.
Researcher Recognition
We maintain a researcher recognition programme to acknowledge those who have made responsible disclosures. With your permission, we will acknowledge your contribution by name (or alias) and a brief description of the finding.
Threatstealth does not currently operate a paid bug bounty programme, but we deeply value the security research community and are committed to treating all reports with respect and transparency.
Encryption
If your report contains sensitive details, please contact our security team directly at security@threatstealth.com. Our security team's address is also listed in security.txt.