Updated on
August 30, 2023
Zluri is committed to ensuring the safety and security of our customers and the integrity of data. We recognize the valuable role of the security research community and we welcome reports from researchers, both of potential vulnerabilities in our systems and of confidential data from or relating to our services that may be accessible by unauthorized persons. If you’ve discovered any security vulnerabilities associated with any of our services, we do appreciate your help in disclosing it to us in a responsible manner. We aim to foster an open partnership with the security community, and we recognize that the work the community does is important in continuing to ensure safety and security for all of our customers. We have developed this policy to both reflect our corporate values and to uphold our legal responsibility to good-faith security researchers that are providing us with their expertise.
Scope
Zluri’s Responsible Disclosure Policy covers the following products:
We intend to increase our scope as we build capacity and experience with this process. Researchers who submit a vulnerability report to us will be given full credit on our website once the submission has been accepted and validated by our product security team.
Out of Scope
Zluri’s static website
Any services hosted by third party providers and services not provided by Zluri.
Legal Posture
Zluri will not engage in legal action against individuals who submit vulnerability reports through our Vulnerability Reporting inbox. We openly accept reports for the currently listed Zluri products. We agree not to pursue legal action against individuals who:
How to Submit a Vulnerability
To submit a vulnerability report to Zluri’s Product Security Team, please utilize the following email dpo@zluri.com.
Preference, Prioritization, and Acceptance Criteria
We will use the following criteria to prioritize and triage submissions.
What we would like to see from you:
What you can expect from Zluri:
If we are unable to resolve communication issues or other problems, Zluri may bring in a neutral third party to assist in determining how best to handle the vulnerability.