Vulnerability Disclosure Policy
Publisher: Psychz Networks, April 25,2019If you believe you have discovered a vulnerability in a Psychz Networks's product or have a security incident to report, please submit a ticket by registereing at https://www.psychz.net/dashboard/client/web/site/signup or contact us without the sign up process - https://www.psychz.net/contact.html.
If you feel the need, please use our PGP public key to encrypt your communications with us. Please request the PGP public key in your initial contact with us.
Once we have received a vulnerability report, Psychz Networks takes a series of steps to address the issue:
- Psychz Networks requests the reporter to keep any communication regarding the vulnerability confidential.
- Psychz Networks investigates and verifies the vulnerability.
- Psychz Networks addresses the vulnerability and releases an update or patch to the code.
- Psychz Networks publicly announces the vulnerability in the release notes of the update via client dashboard. Release notes (and blog posts when issued) include a reference to the person/people who reported the vulnerability, unless the reporter(s) would prefer to stay anonymous.
We greatly appreciate the efforts of security researchers and discoverers who share information on security issues with us, giving us a chance to improve our products and services, and better protect our customers. When properly notified of legitimate issues, we’ll do our best to acknowledge your emailed report, assign resources to investigate the issue, and fix potential problems as quickly as possible.