VVenstap

Responsible Disclosure Policy

Last updated: September 19, 2026

1. Our Commitment

As a security company, we take vulnerabilities in our own platform seriously and welcome reports from security researchers who follow responsible disclosure practices.

2. Scope

This policy covers the Venstap web console, mobile applications, desktop client, and public API. It does not cover customer-configured assets or third-party services we integrate with.

3. How to Report

Email security@venstap.com with a description of the issue, steps to reproduce, and any relevant proof of concept. Please do not include real customer data in your report.

4. What We Ask

  • Give us reasonable time to investigate and remediate before public disclosure
  • Avoid accessing or modifying data that does not belong to you
  • Do not perform testing that degrades service availability for other customers

5. What You Can Expect

We aim to acknowledge reports within 3 business days and provide a status update within 10 business days. We do not currently operate a paid bug bounty program but will credit researchers who wish to be acknowledged.

This document is a template provided for convenience and does not constitute legal advice. Review with qualified counsel before relying on it for compliance purposes.