Vulnerability Disclosure Policy

Powerful Web is committed to maintaining the security, integrity, and availability of our systems, services, applications, and customer data. We value the security research community and encourage responsible reporting of security vulnerabilities.

This Vulnerability Disclosure Policy (“VDP”) explains:

  • How security researchers, customers, and third parties may report vulnerabilities;
  • The process Powerful Web follows to investigate and remediate reported issues; and
  • The expectations and protections applicable to responsible security research activities.

Scope

This policy applies to vulnerabilities affecting:

  • Powerful Web production systems;
  • Customer-facing applications and APIs;
  • Hosted infrastructure and cloud services operated by Powerful Web;
  • Official company websites and web applications;
  • Mobile applications published by Powerful Web;
  • Authentication and authorization systems; and
  • Any other digital assets explicitly designated by Powerful Web as in scope.

Out of Scope

The following activities and findings are generally considered out of scope:

  • Social engineering attacks against employees or customers;
  • Physical security attacks;
  • Denial-of-service (DoS/DDoS) testing;
  • Spam or phishing campaigns;
  • Vulnerabilities requiring physical access to a user’s device;
  • Issues affecting unsupported or outdated browsers;
  • Missing best practices without demonstrable security impact;
  • Rate limiting or brute force issues without evidence of exploitability;
  • Vulnerabilities in third-party services outside Powerful Web’s control; and
  • Automated scanner output without validated impact.

Reporting a Vulnerability

Security vulnerabilities should be reported promptly to:

Email: support@powerfulweb.com

Researchers should include:

  • A clear description of the vulnerability;
  • The affected asset, URL, API, or service;
  • Step-by-step reproduction instructions;
  • Proof-of-concept code, screenshots, or logs where applicable;
  • The potential impact of the issue;
  • Suggested mitigations if available; and
  • Contact information for follow-up communications.

Expectations for Security Researchers

We ask researchers to:

  • Act in good faith;
  • Avoid privacy violations, service disruption, and data destruction;
  • Access only the minimum data necessary to demonstrate the vulnerability;
  • Immediately stop testing if unintended access to customer data occurs;
  • Not modify, copy, retain, or disclose customer information;
  • Avoid degrading system performance;
  • Keep vulnerability details confidential until remediation is complete; and
  • Provide reasonable time for investigation and remediation before public disclosure.

Safe Harbor

Powerful Web will not pursue legal action against individuals who:

  • Conduct security research in good faith;
  • Comply with this policy;
  • Avoid causing harm to customers, systems, or data; and
  • Promptly report discovered vulnerabilities.

Researchers must not:

  • Exfiltrate customer data;
  • Persist access to systems;
  • Use vulnerabilities for extortion;
  • Violate applicable laws or regulations; or
  • Disrupt services or operations.

Activities outside this policy may result in legal or administrative action.

Internal Handling Procedures

Upon receipt of a vulnerability report, Powerful Web will:

Acknowledgment: Confirm receipt of the report within five (5) business days.

Triage and Validation

  • Assess the validity, severity, exploitability, and impact of the reported issue;
  • Assign internal ownership to the appropriate engineering or security team; and
  • Determine remediation priority using industry-standard risk assessment methods (such as CVSS where applicable).

Remediation

  • Develop and deploy corrective actions;
  • Validate remediation effectiveness; and
  • Monitor for evidence of exploitation if necessary.

Communication

  • Provide status updates to the reporter when appropriate;
  • Coordinate disclosure timelines if public disclosure is planned; and
  • Notify affected customers where legally or contractually required.

Disclosure Policy

Powerful Web supports coordinated vulnerability disclosure. Public disclosure of vulnerabilities should not occur until:

  • Powerful Web has confirmed remediation; or
  • A mutually agreed disclosure timeline has elapsed.

Powerful Web reserves the right to publish security advisories, CVEs, or remediation notices as appropriate.

Customer Reporting Procedures

Customers who identify suspected security vulnerabilities should:

  1. Immediately report the issue to support@powerfulweb.com;
  2. Include all relevant technical details and reproduction steps;
  3. Avoid sharing sensitive information through unsecured channels; and
  4. Refrain from publicly disclosing the issue until investigation is complete.

Customers may also report:

  • Account compromise concerns;
  • Unauthorized access attempts;
  • Data exposure incidents; and
  • Abuse of Powerful Web services.

Incident Response Integration

Validated vulnerabilities may trigger the Powerful Web Incident Response Process, including:

  • Security incident classification;
  • Containment and eradication procedures;
  • Customer notification workflows;
  • Regulatory reporting obligations; and
  • Post-incident review and corrective actions.

Data Handling and Confidentiality

Information submitted through the vulnerability reporting process will be handled confidentially and shared only with personnel or partners necessary to investigate and remediate the issue.

Powerful Web may retain submitted information for:

  • Security investigations;
  • Compliance obligations;
  • Legal requirements; and
  • Product improvement efforts.

Recognition and Bug Bounty

At this time, Powerful Web may recognize researchers for valid submissions at its discretion. Eligibility for any future bug bounty or reward program will be governed by separate program terms.

Policy Updates

Powerful Web may modify this policy periodically. Updated versions will be published on the company website with the effective revision date.

Effective Date: December 18, 2023