Loading...

Responsible Vulnerability Disclosure Policy

Supporting Security Researchers in Reporting Potential Vulnerabilities

Our Commitment to Security

At General Telecom Inc. (GTI), we take the security of our systems and data seriously. We value the security research community and believe that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our customers and users.

This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.

Responsible Disclosure Guidelines

We ask that security researchers:

  • Report vulnerabilities privately to our security team before public disclosure
  • Provide detailed information about the vulnerability, including steps to reproduce
  • Allow reasonable time (90 days) for us to address the issue before public disclosure
  • Make good faith efforts to avoid privacy violations, data destruction, or service disruption
  • Do not exploit the vulnerability beyond what is necessary to demonstrate the issue
  • Do not access or modify data that does not belong to you

How to Report a Vulnerability

Report a Security Issue

Please report security vulnerabilities through our contact form. Our security team will review your submission promptly.

Report

Report Contents

Please include the following in your report:

  • Type of vulnerability
  • Affected system(s) or URL(s)
  • Detailed steps to reproduce
  • Proof of concept (if applicable)
  • Potential impact assessment
  • Any suggested remediation steps

Our Response Process

When you report a vulnerability, here's what you can expect from us:

1
Acknowledgment

Initial response within 48 hours

2
Assessment

Evaluate severity and impact

3
Remediation

Develop and deploy fix

4
Notification

Update you when resolved

Safe Harbor

GTI commits to the following safe harbor for security researchers who:

  • Make a good faith effort to comply with this policy
  • Do not intentionally cause harm or violate privacy
  • Report vulnerabilities promptly and responsibly

We will not: Pursue legal action against researchers who follow this policy, and we will work with you to understand and resolve the issue quickly.

Recognition

We appreciate the efforts of security researchers who help us maintain the security of our systems. With your permission, we will acknowledge your contribution in our security acknowledgments page (coming soon).

While we do not currently offer a bug bounty program, we are grateful for responsible disclosure and will work with you throughout the process.

Top