VendorX is committed to the security of our platform and the data entrusted to us by our partners and their customers. We welcome and encourage security researchers to help us improve our security posture through responsible vulnerability disclosure.
This policy applies to vulnerabilities discovered in the following systems and services owned and operated by VendorX Platform, Inc.:
The following are explicitly out of scope for this policy:
VendorX considers security research conducted in accordance with this policy to be authorized, and we will not pursue legal action against researchers who act in good faith. Specifically:
To qualify for safe harbor protections, researchers must:
Submit vulnerability reports via email to security@vendorxpro.com. Please include:
VendorX commits to the following response timelines:
VendorX follows a coordinated disclosure model. We request that researchers allow us 90 calendar days from the date of the initial report to remediate the vulnerability before any public disclosure. If we are unable to remediate within 90 days, we will work with the reporter to agree on a mutually acceptable disclosure timeline.
We will credit researchers who report valid vulnerabilities (with their permission) in our security acknowledgments unless they prefer to remain anonymous.
The following issue types are generally not considered qualifying vulnerabilities under this policy:
Send your report to our security team. We acknowledge all reports within 2 business days.
security@vendorxpro.com