1. Our commitment
We welcome reports from security researchers. If you report a suspected vulnerability in good faith and in accordance with this policy, we will not pursue legal action against you, will not ask your internet provider to identify you, and will work with you to understand and resolve the issue.
2. How to report
Email security@aegisone.lynxclub.ph. Please include:
- The affected component, URL or API endpoint.
- A clear description of the issue and its likely impact.
- Steps that reproduce the behaviour, including any proof-of-concept.
- What you were able to access or affect.
- How you would like to be credited, if at all.
Please report in English where you can, and give us a reasonable opportunity to remediate before disclosing publicly.
3. What you can expect
- Acknowledgement of your report within [acknowledgement period] business days.
- An initial assessment, including whether we consider the issue in scope and our provisional severity, within [triage period] business days.
- Progress updates at reasonable intervals until the issue is resolved or closed.
- Credit in our advisories where you want it, and coordination on timing of any public disclosure.
We do not currently operate a paid bug bounty programme. We will say so plainly rather than imply otherwise.
4. Scope
In scope: the AegisOne platform, the operator console, the public API, the endpoint agent, and this website.
Out of scope: findings from automated scanners without demonstrated impact; missing security headers or cookie flags with no exploitable consequence; email configuration issues without a demonstrated attack; social engineering of our staff or customers; physical attacks; denial of service; issues in third-party services we do not control; and reports concerning software versions alone with no proven exploitability.
Testing against a customer tenancy is out of scope unless that customer has authorised it in writing and has told us.
5. Rules of engagement
When testing, please:
- Use only accounts and data you own or have been given permission to use.
- Access only the minimum data needed to demonstrate the issue, and stop as soon as it is demonstrated.
- Never modify, delete or exfiltrate data that is not yours.
- Never degrade the service for others: no denial of service, no load testing, no spam.
- Delete any data you obtained as soon as the report is closed, and tell us you have done so.
Activity that goes beyond these rules is not protected by this policy and is treated as a breach of the Acceptable Use Policy.
6. Safe harbour
We consider research conducted in accordance with this policy to be authorised access. If a third party brings legal action against you for research conducted within this policy, we will make it known that your activity was authorised.
This policy does not authorise action against any party other than us, and does not override the law of your jurisdiction.