Vulnerability Disclosure Policy
Last updated: July 2026
1. Scope
This policy covers security vulnerabilities affecting AftPak’s public website (aftpak.com), the Client Portal, and any API or webhook endpoint we operate. It does not cover client-specific deployments, on-premise systems, or third-party services we integrate with unless the vulnerability originates in code we control.
2. How to Report
Email inquiries@aftpak.com with a description of the vulnerability, the steps to reproduce it, and its potential impact. Please report privately — do not disclose the issue publicly or to third parties until we have had a reasonable opportunity to address it.
3. Safe Harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: testing only against in-scope systems, avoiding privacy violations and service disruption, and not accessing or modifying data beyond what is strictly necessary to demonstrate the vulnerability.
4. Response Timeline
We aim to acknowledge reports within 3 business days and provide an initial assessment within 10 business days. Resolution timelines depend on severity and complexity — we will keep you informed of progress until the issue is resolved.
5. Out of Scope
Denial-of-service testing, social engineering or phishing of our staff or clients, physical security testing, and automated scanning that generates significant traffic are out of scope and should not be attempted without prior written authorization.
6. Recognition
We do not currently operate a paid bug bounty program. With your permission, we’re happy to credit valid reports in our changelog or acknowledge them privately, whichever you prefer.