Legal
Vulnerability disclosure
If you have found a security issue in something we run, this page tells you where to send it, what we will do with it, and what we will not do to you.
Why this page exists
Our cybersecurity division tells clients to publish one of these before they fund a bug bounty, on the argument that a policy converts a finder into a reporter and money only converts a reporter into a queue. It would be difficult to keep saying that without publishing our own. This policy covers computingamerica.com, hardware.computingamerica.com, it.computingamerica.com and cyber.computingamerica.com and the infrastructure directly behind them.
It is written to the shape the standards ask for: a stated scope, a stated commitment, a stated safe harbour, and a machine-readable pointer at /.well-known/security.txt so a researcher does not have to guess at an address.
In scope
The four sites above and the services that serve them. In practice that is a statically prerendered marketing site with exactly one endpoint that changes state — the contact form — so the surface is small and we would rather say so than let you spend a weekend discovering it.
- The websites themselves, including the contact form and its anti-abuse controls.
- Our DNS, email authentication and certificate configuration.
- Anything we publish that leaks information it should not: a credential, an internal hostname, customer data.
Out of scope
These are out of scope because a report about them cannot lead to a fix on our side, not because we think they are unimportant.
- Client systems we built or assess. If you have found something in one of those, tell us and we will route it, but test it only under that client’s own authorization — not ours.
- Findings from a scanner with no demonstrated impact: a missing header, a cookie flag, a version banner, a TLS configuration that scores below an A.
- Denial of service, load testing, and anything that degrades the service for other people.
- Social engineering of our staff or clients, physical access attempts, and anything touching an account that is not yours.
- Vulnerabilities in third-party platforms we use. Report those to the platform; tell us if the exposure is ours.
Safe harbour
If you make a good-faith effort to stay inside the scope above, we will not pursue or support legal action against you for your research, and we will say so in writing if a third party asks. Good faith means: you stop when you have demonstrated the issue rather than pressing on to see how far it goes, you do not access, modify or retain anyone else’s data, you do not degrade the service, and you give us a reasonable opportunity to fix the issue before you make it public.
This is not a licence to test anything else we touch. It covers the assets named on this page and nothing beyond them.
How to report
Email info@computingamerica.com. Send us what you did, in enough detail that we can do it again: the request, the response, and what the impact is if someone hostile did the same thing. A short report with one reproducible finding is worth more to us than a long one with ten possibilities, and it is what we ask of ourselves when we report to somebody else.
Tell us in the same message how you would like to be credited, and whether you intend to publish. If you would prefer to encrypt, ask and we will arrange it.
What we commit to
These are the numbers we hold ourselves to. If we miss one, the delay will be explained rather than silent.
- Acknowledgement within three business days.
- A decision — accepted, or closed with the reasoning — within ten business days.
- A fix, or a stated plan with a date, within ninety days of acceptance for anything we accept as valid.
- Credit where you want it, and no obligation to accept it where you do not.
- An honest verdict. If we close your report because it does not cross a trust boundary or has no impact we can demonstrate, we will tell you exactly that and why, rather than letting it age quietly.
What we do not offer
There is no monetary reward. We would rather publish that plainly than imply one: a bounty buys volume, volume has to be triaged, and a firm of our size adding a reward before it has proved it can answer the queue would be doing the thing we advise clients against. If that changes, this page changes with it.