1. Scope
Vantage is a Visium company. Visium operates the Vantage website and services. In this policy, “Visium,” “we,” “us” and “our” mean Visium, and “Vantage” means the Vantage products and services.
This policy covers vantagesensing.com and the services we operate for Vantage. We welcome reports from security researchers, agencies and anyone else who finds a weakness. A machine-readable version of our contact details is published at https://vantagesensing.com/.well-known/security.txt.
This page is for reporting vulnerabilities. Agencies with questions about how Vantage protects sessions and records can raise them in a briefing.
2. How to report
Email legal@vantagesensing.com with “Security” in the subject line. Please include:
- the URL or service affected;
- a description of the issue and its likely impact;
- the steps needed to reproduce it, with any proof of concept or screenshots; and
- whether and how you would like to be credited.
If the issue exposes sensitive data, describe the data rather than including it in your report.
3. Guidelines for research
When you look for and report issues, we ask that you:
- act in good faith, to find and report issues rather than to exploit them;
- access no more data than you need to show the issue, and stop once you have shown it;
- avoid viewing, changing, keeping or sharing data that does not belong to you. If you come across personal or agency information, stop, tell us, and delete any copy you hold;
- avoid destroying or degrading data or systems;
- avoid denial of service testing and anything else that degrades service for others;
- avoid social engineering, phishing and physical attacks against our people, facilities or partners; and
- give us reasonable time to fix the issue before any public disclosure, as described in section 7.
If you are not sure whether something is allowed, ask us first at legal@vantagesensing.com.
4. Out of scope
The following are outside this policy, or are not usually treated as vulnerabilities:
- websites and services that we do not operate, including our hosting provider’s platform, our email provider and Google Fonts. Please report those to their owners;
- denial of service and volume-based attacks;
- social engineering, phishing and physical attacks;
- output from automated scanners without a demonstrated impact;
- missing security headers or best-practice settings without a demonstrated way to exploit them;
- clickjacking on pages with no sensitive actions;
- email configuration findings, such as SPF, DKIM or DMARC settings, without a demonstrated impact;
- software version or banner disclosure without a working exploit;
- issues that require physical access to a device, or an already compromised device or account; and
- the briefing request form opening your own email app, which is how it is designed to work.
5. Our commitments
If you report an issue under this policy, we will:
- acknowledge your report within three business days;
- keep you updated as we investigate and fix the issue;
- credit you for the discovery, if you want to be credited; and
- not pursue legal action against you for good-faith research that follows this policy.
6. Safe harbor
We consider security research that is conducted in good faith and follows this policy to be authorized, including under the Computer Fraud and Abuse Act and similar state laws. We will not pursue legal action against you for that research, including under the anti-circumvention provisions of the Digital Millennium Copyright Act, and we will not ask law enforcement to act against you for it. If someone else brings legal action against you for research that followed this policy, we will make it known that we authorized it.
This safe harbor covers only claims that Visium could bring. We cannot authorize research on systems that others operate.
7. Coordinated disclosure
Please give us reasonable time to fix an issue before you disclose it publicly. Unless we agree on a different timeline, we ask for 90 days from the date of your report. If we need more time, we will tell you why and work with you on a date.
8. Bug bounty
We do not offer a paid bug bounty at this time. We are grateful for every good-faith report, and we will credit researchers who want to be credited.