Responsible Vulnerability Disclosure Policy
Supporting Security Researchers in Reporting Potential Vulnerabilities
Our Commitment to Security
At General Telecom Inc. (GTI), we take the security of our systems and data seriously. We value the security research community and believe that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our customers and users.
This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.
Responsible Disclosure Guidelines
We ask that security researchers:
- Report vulnerabilities privately to our security team before public disclosure
- Provide detailed information about the vulnerability, including steps to reproduce
- Allow reasonable time (90 days) for us to address the issue before public disclosure
- Make good faith efforts to avoid privacy violations, data destruction, or service disruption
- Do not exploit the vulnerability beyond what is necessary to demonstrate the issue
- Do not access or modify data that does not belong to you
How to Report a Vulnerability
Report a Security Issue
Please report security vulnerabilities through our contact form. Our security team will review your submission promptly.
ReportReport Contents
Please include the following in your report:
- Type of vulnerability
- Affected system(s) or URL(s)
- Detailed steps to reproduce
- Proof of concept (if applicable)
- Potential impact assessment
- Any suggested remediation steps
Our Response Process
When you report a vulnerability, here's what you can expect from us:
Acknowledgment
Initial response within 48 hours
Assessment
Evaluate severity and impact
Remediation
Develop and deploy fix
Notification
Update you when resolved
Safe Harbor
GTI commits to the following safe harbor for security researchers who:
- Make a good faith effort to comply with this policy
- Do not intentionally cause harm or violate privacy
- Report vulnerabilities promptly and responsibly
We will not: Pursue legal action against researchers who follow this policy, and we will work with you to understand and resolve the issue quickly.
Recognition
We appreciate the efforts of security researchers who help us maintain the security of our systems. With your permission, we will acknowledge your contribution in our security acknowledgments page (coming soon).
While we do not currently offer a bug bounty program, we are grateful for responsible disclosure and will work with you throughout the process.