Vulnerability Disclosure Policy
We welcome reports from security researchers. If you believe you have found a vulnerability in a SnapFixx system, we want to hear from you.
How to report
Email security@snapfixx.ca with:
- A description of the issue and where you found it
- Steps to reproduce, with any proof-of-concept you can share
- The potential impact as you assess it
- How you would like to be credited, if at all
What we commit to
| Stage | Our target |
|---|---|
| Acknowledge your report | Within 3 business days |
| Initial assessment and severity | Within 10 business days |
| Progress updates | Every 14 days until resolved |
| Remediation of critical issues | As quickly as practicable, prioritised above other work |
Safe harbour
If you make a good-faith effort to comply with this policy while researching, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue quickly. If a third party brings action against you for activity conducted under this policy, we will make it known that your actions were authorised.
Scope
In scope: snapfixx.ca and its subdomains, the SnapFixx and SnapFixx Pro mobile applications, and our public APIs.
Out of scope: findings from automated scanners without demonstrated impact, social engineering of our staff or professionals, physical attacks, denial-of-service testing, spam, and vulnerabilities in third-party services we do not control.
Please do not
- Access, modify, or delete data belonging to anyone other than yourself. If you encounter personal information, stop and tell us immediately.
- Degrade or interrupt our services for others.
- Publicly disclose the issue before we have had a reasonable opportunity to fix it.
Recognition
We do not currently operate a paid bug bounty. We do maintain a acknowledgements list and will credit you there if you would like, once the issue is resolved.