Sacramento, California Mon to Fri, 9:00 AM to 6:00 PM Pacific
DotNet Holdings

Trust Center

Vulnerability disclosure policy

We take the security of our systems seriously, and we value the work of security researchers. If you believe you have found a vulnerability in a DotNet Holdings website or service, we want to hear from you.

Key takeaways

  • Report vulnerabilities to security@dotnetholdings.com.
  • We support good faith research and will not pursue legal action against researchers who follow this policy.
  • Give us reasonable time to investigate and remediate before public disclosure.
  • Do not access, modify, or delete data that is not yours, and do not degrade our services.

How to report

Send your report to security@dotnetholdings.com. Please include the affected site or service, a clear description of the issue, the steps to reproduce it, and any supporting material such as screenshots or a proof of concept. The more detail you provide, the faster we can validate and fix the issue.

Our commitment

When you report an issue in good faith under this policy, we will acknowledge your report, keep you informed as we investigate, work to remediate valid issues in a reasonable timeframe, and credit you if you wish once the issue is resolved. We will not pursue or support legal action against you for research and disclosure conducted in accordance with this policy.

Guidelines for researchers

To keep research safe for everyone, please:

  • give us a reasonable opportunity to remediate before disclosing an issue publicly;
  • avoid privacy violations, and do not access, modify, or delete data that does not belong to you;
  • do not degrade, disrupt, or overload our services, and avoid automated testing that could do so;
  • do not use social engineering, physical attacks, or denial of service techniques;
  • use only your own accounts or test accounts for testing.

Scope

This policy covers the public websites and services operated by DotNet Holdings. Some of the companies we operate run their own products and may have their own reporting channels. If you are unsure where an issue belongs, send it to us and we will route it to the right team.

Vendor review

Need documentation for a review?

Security package, Data Processing Addendum, subprocessor list, accessibility VPAT, certificate of insurance, or a completed questionnaire. Tell us what your team needs.