SECURITY AT SECURITYTALENT
Vulnerability Disclosure Policy
Security is a shared responsibility. We welcome clear, good-faith reports that help us protect members, organizations and the wider cybersecurity community.
If you follow this policy, SecurityTalent will treat your research as authorized, work with you to understand the issue and will not initiate or recommend legal action solely for that good-faith research.
Scope of this policy
Test only assets owned and operated by SecurityTalent. When ownership is unclear, ask before testing.
In scope
- securitytalent.com and its owned subdomains
- First-party SecurityTalent web features and APIs
- Authentication, authorization, privacy and data-isolation weaknesses
- Vulnerabilities with a reproducible security impact
Out of scope
- Third-party services, vendors or member-owned systems
- Social engineering, phishing or physical attacks
- Denial of service, traffic flooding, spam or destructive testing
- Automated scanning that degrades service or produces excessive requests
- Reports based only on missing headers, version banners or theoretical risk without impact
Research guidelines
- Notify us promptly after discovering a real or potential issue.
- Use the minimum testing needed to confirm the vulnerability. Do not establish persistence, pivot to other systems or exfiltrate data.
- Use only accounts you own or have explicit permission to test.
- Avoid privacy violations, service disruption and any destruction, modification or retention of data.
- Do not access, download or share another person’s information. If you encounter it, stop immediately.
- Give us reasonable time to investigate and remediate before any public disclosure.
- Comply with applicable law and do not violate the rights of third parties.
How to report a vulnerability
Email the report to
- Affected URL, feature or asset
- Vulnerability type and expected security impact
- Clear, reproducible steps and any required test account context
- Redacted screenshots, request/response details or proof of concept
- Whether you believe the issue is being actively exploited
- Your preferred name for acknowledgement, or a request to remain anonymous
What to expect from us
Complex issues may take longer. We prioritize by likely impact, exploitability and risk to members, and we may ask for limited additional information.
Coordinated disclosure
Please allow up to 90 calendar days before public disclosure, unless we agree to another date. Timing may change for actively exploited issues, third-party dependencies or unusually complex remediation. We will not ask you to hide a valid issue indefinitely.
Good-faith safe harbor
Research consistent with this policy is considered authorized by SecurityTalent. If a third party brings legal action related to policy-compliant research, we will make our authorization known. This safe harbor cannot bind third parties or excuse violations unrelated to this policy.
Recognition and rewards
This is a vulnerability disclosure program, not a paid bug-bounty program. SecurityTalent does not promise payment. With your permission, we may acknowledge a helpful report after remediation.
Confidentiality and report data
We use submitted details to investigate, remediate and communicate about the issue. Limit personal or sensitive information in your report. We may share necessary details with a service provider or affected third party solely to coordinate remediation.
Thank you for helping SecurityTalent improve its security through careful, responsible research.






