Skip to content
NOW AVAILABLE Feature Release! Learn About Our Enhanced Capabilities for Prioritizing Remediation Learn more >>

Vulnerability Disclosure Policy

Last updated: September 12th, 2024

Introduction

PlexTrac is committed to ensuring the security of our clients by protecting their sensitive information.

This policy is intended to provide security researchers with clear guidelines for conducting vulnerability discovery activities and to convey our preferences for reporting vulnerabilities within the platform.

The Vulnerability Disclosure Policy describes the different systems and types of research PlexTrac authorizes, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.

We encourage you to contact us to report potential vulnerabilities in our systems and ask any questions you may have.

Authorization

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve issues quickly, and PlexTrac will not recommend or pursue legal action related to your research.

Should legal action be initiated by a third-party against you for activities that were conducted in accordance with this policy, we will make our authorization known.

Guidelines

Under this policy, research includes activities in which you:

  • If you intend to perform dynamic analysis or other methods which may raise alarms, please provide advanced notification to security@plextrac.com.
  • Notify us as soon as possible after you discover a real or potential vulnerability.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or ex-filtrate data, establish persistent command line access, or use the exploit to pivot to other systems.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Do not submit a high volume of low-quality reports.

Once you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else without written consent.

Test methods

The following testing methods are NOT considered authorized:

  • Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data
  • Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing

Scope

This policy applies to the following systems and services:

This policy excludes the following systems and services:

  • Any other URL or asset owned by PlexTrac or its clients.
  • Any service not expressly listed above.

Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any).

If you aren’t sure whether a system is in scope or not, contact us at security@plextrac.com before starting your research.

Though we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document.

If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We will increase the scope of this policy over time as required.

Exclusions

PlexTrac accepts reports for bugs of all shapes and sizes; however, please note that findings which are classified as “Low” or “Informational” are currently not eligible for swag/rewards. We will work through these submissions as time permits.

Examples of items falling within this category:

  • HTTP Header misconfigurations
  • DMARC Policy enforcement issues
  • Findings identified as a “P4” or “P5” within Bug Crowd’s Vulnerability Rating Taxonomy (VRT)
  • Findings identified as “None” or “Low” Severity in HackerOne’s severity rating system
  • Findings with a CVSS score < 4.0
  • Self XSS or DOM XSS with low likelihood or impact

Reporting a vulnerability

Information submitted under this policy will be used for defensive purposes only — to mitigate or resolve vulnerabilities.

We accept vulnerability reports via email to security@plextrac.com and we will acknowledge receipt of your report within 5 business days.

By submitting a vulnerability, you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against PlexTrac related to your submission.

What we would like to see from you

In order to help us triage and prioritize submissions, we recommend that your reports:

  • Describe the location in which the vulnerability was discovered and the potential impact of exploitation.
  • Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).
  • During remediation efforts PlexTrac expects that you will not be publishing any exploits, proofs of concept, or write-ups about reported vulnerabilities prior to receiving written notice of successful remediation.
    • Failure to adhere to this requirement will be considered a breach of the policy and any associated research considered unauthorized.

What you can expect from us

When you choose to share the results of your research with us, we commit to coordinating with you as openly and as quickly as possible.

  • Within 5 business days, we will acknowledge that your report has been received.
  • To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including issues or challenges that may delay resolution.
  • We will maintain an open dialogue to discuss issues.
  • We offer PlexTrac branded merchandise to researchers as a means of showing our appreciation for your efforts that may include the following:
    • PlexTrac T-Shirts
    • Gift cards
    • Other items as available

Questions

Questions regarding this policy may be sent to security@plextrac.com. We also invite you to contact us with suggestions for improving this policy.

Policy History

  • 2021-08-06 – Initial policy draft
  • 2021-10-07 – Policy review, scope change
  • 2021-11-22 – Final review, scope and format adjustments
  • 2023-04-18 – Scope change
  • 2024-08-12 – Scope changes (exclusions)