Responsible Disclosure Policy
At Elyments, we consider the security of our users and our platform a top priority. If you believe that you have discovered a potential vulnerability on our platform or in any APIs, apps or Elyments servers or any other assets please inform us via [email protected]. We would like to know about it so we can take steps to address it as quickly as possible.
We would appreciate your help in security Elyments by revealing your findings in accordance with this policy.
Please do the following:
-
E-mail your findings to [email protected]. Encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands
- Do not exploit the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or deleting or modifying other people's data
- Do not reveal the problem to others until it has been resolved
- Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties, and
- Do provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation
- Provide us with information required to contact you (at least telephone number or email address)