Skip to main content
Legal

Vulnerability Disclosure Policy

Last updated: July 2026

1. Scope

This policy covers security vulnerabilities affecting AftPak’s public website (aftpak.com), the Client Portal, and any API or webhook endpoint we operate. It does not cover client-specific deployments, on-premise systems, or third-party services we integrate with unless the vulnerability originates in code we control.

2. How to Report

Email inquiries@aftpak.com with a description of the vulnerability, the steps to reproduce it, and its potential impact. Please report privately — do not disclose the issue publicly or to third parties until we have had a reasonable opportunity to address it.

3. Safe Harbor

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: testing only against in-scope systems, avoiding privacy violations and service disruption, and not accessing or modifying data beyond what is strictly necessary to demonstrate the vulnerability.

4. Response Timeline

We aim to acknowledge reports within 3 business days and provide an initial assessment within 10 business days. Resolution timelines depend on severity and complexity — we will keep you informed of progress until the issue is resolved.

5. Out of Scope

Denial-of-service testing, social engineering or phishing of our staff or clients, physical security testing, and automated scanning that generates significant traffic are out of scope and should not be attempted without prior written authorization.

6. Recognition

We do not currently operate a paid bug bounty program. With your permission, we’re happy to credit valid reports in our changelog or acknowledge them privately, whichever you prefer.