We take the security of our customers' confidential documents seriously and welcome good-faith research that helps us keep them safe. This policy explains how to report a vulnerability and what you can expect from us.
How to report
Email security@sifrsys.com with a description of the issue, the steps to reproduce it, and its potential impact. Please encrypt sensitive details on request. Our machine-readable contact is at /.well-known/security.txt.
Our commitment
- We will acknowledge your report within 3 business days.
- We will keep you informed as we investigate and remediate.
- We will not pursue legal action against researchers who follow this policy in good faith.
- We are happy to credit you once the issue is resolved, if you wish.
Please do
- Give us a reasonable time to remediate before any public disclosure.
- Only test against your own accounts and data.
- Report as soon as you discover a potential issue.
Please do not
- Access, modify, or delete data belonging to other customers.
- Degrade or disrupt our services (no denial-of-service or spam testing).
- Use social engineering, phishing, or physical attacks against our staff or vendors.
- Publicly disclose a vulnerability before we have had a chance to fix it.
Scope
The Sifrsys production application (sifrsys.com and its subdomains) and its API are in scope. Third-party services we rely on (our hosting, database, email, and payment providers) have their own disclosure programs and should be reported to them directly.