Responsible Disclosure Policy
At Sigasi, we prioritize the security and privacy of our customers, users, and systems. We are committed to ensuring that our platforms and applications remain secure. If you believe you’ve found a security vulnerability, we encourage you to report it to us responsibly so we can address it promptly.
How to Report a Vulnerability
If you discover a vulnerability, please submit your findings to us via email at security@sigasi.com.
In your report, please include:
- A detailed description of the vulnerability.
- Steps to reproduce the issue, if possible.
- Any relevant details such as affected systems, tools used, or potential impact.
Our Commitments
- We will respond to your submission within 5 business days to acknowledge receipt.
- We will work diligently to resolve verified issues in a timely manner.
- We will keep you updated on the progress of the resolution.
- We may publicly acknowledge your contribution, but only with your explicit consent.
Scope of the Program
This policy permits vulnerability testing of:
- Our public website at www.sigasi.com .
- Current, in-maintenance releases of Sigasi products, using your own installation and test data.
Other Sigasi-operated websites, servers, and internal systems require prior written authorization before testing. If you are unsure whether an asset is in scope, contact security@sigasi.com first.
The following are outside the scope of this testing permission:
- Third-party services used by Sigasi, unless the service provider separately authorizes your testing.
- Customer-operated environments, installations, accounts, and data.
- Legacy versions of our products.
We welcome reports of vulnerabilities discovered inadvertently in systems outside this scope. Reporting a finding does not authorize further testing or exploitation.
Strictly Prohibited Activities
- Denial of service (DoS) attacks.
- Exploiting vulnerabilities beyond testing purposes.
- Social engineering of employees or users.
- Accessing, modifying, or interfering with data belonging to our customers, users, or systems.
- Exfiltrating sensitive information, even for testing purposes.
Legal Safe Harbor
We will not take legal action against researchers who follow this policy in good faith. Please refrain from violating laws or breaching systems outside the program scope.
Thank you for helping us maintain a secure environment for everyone.
The Sigasi security team