Vulnerability Disclosure
Insites is committed to maintaining the security, integrity and availability of our systems, and to protecting our customers' data.
We do not operate a bug bounty programme, and we do not invite, commission or consent to security testing of our platform. This policy exists so that if you become aware of a vulnerability affecting Insites, there is a clear and proper way to tell us about it, and so that the limits we expect to be respected are set out in advance.
It explains what a report must contain, what we will do with one, and what we will not accept.
This policy is not permission to test. Nothing in it authorises you to access, probe, scan, disrupt or interfere with our systems, our customers' data, or any account that is not your own. Activity outside this policy is unauthorised, and we reserve all rights and remedies in respect of it.
Where you report a vulnerability to us in good faith and you have stayed within the limits below, we will not pursue legal action against you in respect of that report. This applies where you:
- Acted in good faith, with no intent to extort, disrupt, or profit.
- Stopped as soon as you had enough to demonstrate the issue, and went no further.
- Accessed no more data than was strictly necessary, and did not retain, copy or share any of it.
- Caused no degradation to our service and no harm to our customers.
- Reported the issue to us promptly and privately, and kept it confidential.
This protection is limited to the conduct described above. It does not extend to anything beyond it, and it does not apply where these conditions are not met.
If a third party brings legal action against someone who complied with this policy in full, we will confirm that their report was made in accordance with it.
We will accept reports about:
- Public-facing web applications operated by Insites.
- Domains owned and controlled by insites.com.
- Public APIs and documented endpoints.
- Customer-facing dashboards and services.
- Authentication and authorisation mechanisms.
Listing an asset here describes what we are willing to receive a report about. It is not permission to test that asset.
The following are never acceptable and fall outside this policy entirely:
- Social engineering or phishing targeting our employees, contractors, or customers.
- Physical security testing.
- Denial-of-service attacks, stress testing, or anything that degrades performance for others.
- Automated scanning that generates significant traffic.
- Testing against third-party services not owned or operated by Insites, including the websites our customers submit for analysis.
- Accessing, modifying or exfiltrating another user's data.
Email security@insites.com.
Your report must contain enough detail for us to reproduce the issue. As a minimum, tell us:
- The affected URL, API or component.
- What the vulnerability is.
- Step-by-step instructions to reproduce it.
- What someone could actually do with it, and why that matters.
- Any supporting evidence, such as proof-of-concept code, screenshots or logs.
Reports without that detail will not be answered. In particular, we do not respond to:
- Messages stating that a vulnerability exists without saying what it is.
- Requests to agree a reward, or to confirm a bounty, before details will be shared.
- Raw output from an automated scanner, sent without analysis.
- Reports of findings with no demonstrated security impact, such as missing headers or configuration preferences.
We will not enter into any negotiation about payment in exchange for details of a vulnerability.
Please keep the issue confidential and do not disclose it publicly until we have had a reasonable opportunity to remediate it.
Where a report meets the requirements above, we aim to:
- Acknowledge it within five working days.
- Triage and validate the issue.
- Tell you how we have assessed its severity and what we intend to do about it.
- Remediate confirmed vulnerabilities on a timescale proportionate to their severity and to the risk they present.
These are aims rather than commitments, and they do not apply to reports that fall short of the requirements above.
We expect a vulnerability to remain confidential until remediation is complete and our customers are protected. Once an issue is resolved we are willing to discuss whether and when it can be described publicly. We do not accept disclosure deadlines set unilaterally, and publishing before we have remediated falls outside this policy.
We do not operate a bug bounty programme. We may choose to acknowledge a researcher who has made a genuinely useful report, entirely at our discretion. Nothing in this policy creates any expectation or entitlement to payment, recognition or reward.
If you do become aware of a vulnerability:
- Do nothing that affects the availability or performance of the service.
- Do not access or retain sensitive customer data.
- Stop immediately and tell us if you encounter customer data unintentionally.
- Do not attempt to create or obtain an account. Accounts are provisioned to our customers, and there is no self-service sign-up. If you are a customer, stay within your own account and your own data.
- Do not attempt lateral movement, privilege escalation, or persistence beyond what is needed to establish that the issue is real.
By reporting a vulnerability to us, you confirm that you have complied with all applicable laws and regulations, that you have not exploited the issue for financial gain or any malicious purpose, and that the detail you have provided is accurate.
Reporting an issue to us does not entitle you to any payment, and does not transfer to you any right in our systems or data.
We may update this policy from time to time to reflect changes in our security practices. The version on this page is the current one.
Security team: security@insites.com.