Responsible Disclosure Policy
ACGRAM LLC values the work of security researchers and the broader community in helping keep ACGRAM Quotrova™ and our customers safe. This Responsible Disclosure Policy explains how to report a suspected security vulnerability to us.
OUR COMMITMENT
We are committed to working with security researchers who report potential vulnerabilities in good faith. We will acknowledge your report, investigate, and keep you informed of our progress as we work to resolve valid issues.
SCOPE
This policy applies to the ACGRAM Quotrova™ application and its public-facing services operated by ACGRAM LLC. Third-party platforms and services that ACGRAM relies on are governed by their own disclosure programs and are out of scope here.
RESEARCH GUIDELINES
When researching potential vulnerabilities, please:
- Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services;
- Only interact with accounts you own or have explicit permission to access;
- Do not access, modify, or delete data that does not belong to you;
- Do not run automated scans that may degrade service availability;
- Give us a reasonable time to investigate and remediate before any public disclosure.
HOW TO REPORT
Please report suspected vulnerabilities to security@acgram.com with enough detail for us to reproduce the issue — including the affected URL or feature, a description of the vulnerability, and the steps to reproduce it.
SAFE HARBOR
If you make a good-faith effort to comply with this policy during your research, ACGRAM will consider your research to be authorized, will work with you to understand and resolve the issue quickly, and will not pursue or support legal action related to your research.
CONTACT
Security reports: security@acgram.com. ACGRAM LLC, State of Wyoming, USA. Website: https://acgram.com.