Security disclosure policy

If you believe you have found a security vulnerability in any AssurePort property, we want to hear from you. This page is the canonical Policy URL referenced by /.well-known/security.txt (RFC 9116). Read it before you submit.

Language: The English version is the authoritative legal text. Türkçe / Deutsch / Français translations are provided for convenience; in case of conflict the English version prevails.

How to report

Send a single email to abuse@assureport.com with the following:

  • A description of the issue and its impact in your own words.
  • The exact URL or endpoint where the issue lives.
  • Step-by-step reproduction instructions (curl commands, payloads, screenshots).
  • Any account, header, or session data needed to reproduce — we will not penalise you for including credentials you used in testing.
  • Your preferred name for acknowledgment, or "anonymous".

For sensitive reports you may also CC legal@assureport.com. Reports submitted via X / Twitter / Mastodon DMs are not monitored — use email only.

PGP encryption (optional)

If your finding contains material you'd rather not send in plaintext, encrypt it to our disclosure key. Pin the fingerprint out-of-band (any two of: this page, /.well-known/security.txt's Encryption directive, a signed changelog entry, a signed blog post) before trusting it.

Disclosure key (rotated annually)

Fingerprint: 2026 ASSUREPORT DISCLOSURE — KEY ROTATION PENDING

Status: Publication queued for the Sprint 9 trust-anchor rotation. Until the ASCII-armoured block lands here, plaintext to abuse@assureport.com is acceptable — Resend forwards over TLS and the mailbox is monitored by the security on-call rotation.

In scope

SurfaceNotes
assureport.comMarketing surface, free intel APIs, public docs.
app.assureport.comConsole, tenant API, billing flows.
api.assureport.comPublic + tenant APIs.
The PDF / Markdown reports we generateFindings rendering, data exposure across tenants.

Out of scope

  • Volumetric or denial-of-service testing of any AssurePort property.
  • Social engineering of AssurePort staff, contractors, or vendors (Polar.sh, Cloudflare, Anthropic, Fly.io).
  • Physical attacks against any AssurePort office, employee, or supplier.
  • Testing against tenants other than your own — including the platform's "self-pentest" target. Use the free intel toolkit if you want to look at the marketing surface without authentication.
  • Findings only reproducible in vulnerable client browsers we do not target (e.g. browsers older than 24 months, browsers without TLS 1.2 support).
  • Missing security headers on the marketing-only surface that does not handle authenticated data.
  • SPF / DMARC / DKIM policy nitpicks (we are aware; the corporate mail domain runs strict).

Safe harbor

AssurePort considers good-faith security research authorised under this policy to be:

  • Authorised under the Computer Fraud and Abuse Act (CFAA), if you are based in the United States.
  • Authorised under the Computer Misuse Act 1990, if you are based in the United Kingdom.
  • A legitimate purpose under Article 6(1)(f) GDPR (legitimate interests in operating a secure service) for any incidental processing of personal data that occurs while you reproduce a vulnerability.
  • Exempt from any terms of service breach claim we might otherwise raise.

"Good faith" means: you have a real belief in the vulnerability; you stop and report as soon as you confirm exploitability; you do not exfiltrate, modify, retain, or share customer data beyond the minimum needed to demonstrate the issue; and you give us reasonable time to fix before public disclosure.

Response timelines

StageTarget
Acknowledge receipt1 business day
Triage decision (in-scope / not-in-scope / dup)2 business days
Critical / High remediationBest effort within 14 days
Medium / Low remediationBest effort within 60 days
Public disclosureCoordinated; we publish accepted findings after the fix ships

If we miss a target, we will write to you with a status update before the deadline lapses. We do not pay bug bounties at this stage but we will credit you publicly (or keep you anonymous, your choice). Repeat valid reporters become trusted reporters and gain a faster channel.

Acknowledgments

We thank every researcher who reports a real issue here. The hall of fame is currently empty — AssurePort launched in May 2026 and we are early in our public disclosure history. Reports accepted under this policy will be listed below with the date, severity, and a short description of the class of issue.

How a report makes it into the hall

  • The report is in scope per the table above, and the safe-harbor conditions held.
  • We were able to reproduce it from your write-up, or after a reasonable clarification round.
  • A fix shipped to production. The hall entry links to the changelog row.
  • You opted in to public acknowledgment. Anonymous reports still get a fix and a private thank-you; they just don't appear in the table.

Entry format

Each row carries the date the fix shipped, the affected surface, the severity tier we triaged it at, a one-line class-of-issue description, your preferred attribution name, and the changelog cross-link.

ShippedSurfaceSeverityClassReporterChangelog
No external reports accepted yet — first entry pending.

Internal findings from the platform's self-pentest (Sprint 6 onward) are published separately — this table is reserved for external researchers under this policy.

Legal basis

This policy is referenced by https://assureport.com/.well-known/security.txt under RFC 9116. It is binding on AssurePort with respect to good-faith researchers who follow it. It does not waive criminal liability for actions outside its scope (e.g. denial of service, accessing other tenants' data, harming customers). It does not create employment, agency, or contractor relationships.

Last updated 2026-05-14. Policy revisions will not retroactively withdraw safe-harbor protection for reports that were already in good-faith progress.

Güvenlik açığı bildirim politikası

Herhangi bir AssurePort sisteminde veya mülkünde bir güvenlik açığı bulduğunuzu düşünüyorsanız, bunu sizden duymak isteriz. Bu sayfa, /.well-known/security.txt (RFC 9116) tarafından referans gösterilen resmi politika bağlantısıdır (Policy URL). Lütfen bildirimde bulunmadan önce okuyun.

Dil: İngilizce sürüm bağlayıcı olan asıl hukuki metindir. Türkçe / Almanca / Fransızca çeviriler bilgilendirme amaçlı sunulmuştur; herhangi bir çelişki durumunda İngilizce metin geçerlidir.

Nasıl raporlanır?

Aşağıdaki bilgileri içeren tek bir e-postayı abuse@assureport.com adresine gönderin:

  • Bulduğunuz sorunun ve etkisinin kendi cümlelerinizle açıklaması.
  • Sorunun bulunduğu tam URL veya uç nokta (endpoint).
  • Adım adım yeniden üretme (reproduction) talimatları (curl komutları, yükler (payloads), ekran görüntüleri).
  • Yeniden üretmek için gereken herhangi bir hesap, başlık veya oturum verisi — test sırasında kullandığınız kimlik bilgilerini eklediğiniz için size karşı bir yaptırım uygulanmayacaktır.
  • Teşekkür ve atıf için tercih ettiğiniz ad veya "anonim" kalma isteğiniz.

Hassas raporlar için legal@assureport.com adresini de CC'ye ekleyebilirsiniz. X / Twitter / Mastodon DM'leri üzerinden gönderilen bildirimler izlenmemektedir — lütfen yalnızca e-posta kullanın.

PGP şifreleme (isteğe bağlı)

Bulgularınız düz metin olarak göndermek istemediğiniz hassas bilgiler içeriyorsa, bunları bildirim anahtarımızla şifreleyin. Anahtara güvenmeden önce parmak izini harici olarak doğrulayın (şu iki kaynaktan herhangi ikisi: bu sayfa, /.well-known/security.txt dosyasındaki Encryption direktifi, imzalı bir değişiklik günlüğü veya imzalı bir blog yazısı).

Bildirim anahtarı (yıllık olarak yenilenir)

Parmak izi: 2026 ASSUREPORT DISCLOSURE — KEY ROTATION PENDING

Durum: Yayınlama işlemi Sprint 9 güven çıpası (trust-anchor) rotasyonu için sıraya alındı. ASCII zırhlı blok burada yayınlanana kadar, abuse@assureport.com adresine düz metin gönderilmesi kabul edilebilir. E-postalar TLS üzerinden iletilir ve e-posta kutusu nöbetçi güvenlik ekibi tarafından izlenir.

Kapsam dahilinde

BileşenNotlar
assureport.comPazarlama yüzeyi, ücretsiz tehdit istihbaratı API'leri, genel belgeler.
app.assureport.comKonsol, müşteri API'si, faturalandırma akışları.
api.assureport.comGenel ve müşteri API'leri.
Ürettiğimiz PDF / Markdown raporlarıBulguların işlenmesi, müşteriler arası veri sızıntıları.

Kapsam dışı

  • Herhangi bir AssurePort mülküne yönelik hacimsel veya hizmet dışı bırakma (DoS/DDoS) testleri.
  • AssurePort personeline, yüklenicilerine veya tedarikçilerine (Polar.sh, Cloudflare, Anthropic, Fly.io) yönelik sosyal mühendislik saldırıları.
  • Herhangi bir AssurePort ofisine, çalışanına veya tedarikçisine yönelik fiziksel saldırılar.
  • Kendi hesabınız/alanınız dışındaki müşterilere (kiracılara) yönelik testler — buna platformun "kendi kendine sızma testi" hedefi dahildir. Kimlik doğrulaması yapmadan pazarlama yüzeyine bakmak istiyorsanız ücretsiz istihbarat araç setini kullanın.
  • Yalnızca hedeflemediğimiz eski/savunmasız tarayıcılarda (örneğin 24 aydan eski veya TLS 1.2 desteği olmayan tarayıcılar) üretilebilen bulgular.
  • Kimlik doğrulaması gerektiren verileri barındırmayan, yalnızca pazarlama amaçlı alanlardaki eksik güvenlik başlıkları.
  • SPF / DMARC / DKIM politikası hakkındaki küçük pürüzler (durumun farkındayız; kurumsal e-posta alan adımız sıkı kurallarla çalışmaktadır).

Güvenli Liman (Safe Harbor)

AssurePort, bu politika çerçevesinde iyi niyetle gerçekleştirilen güvenlik araştırmalarını şu şekilde değerlendirir:

  • Amerika Birleşik Devletleri'nde yerleşikseniz, Bilgisayar Dolandırıcılığı ve Kötüye Kullanımı Yasası (CFAA) kapsamında izin verilmiş sayılır.
  • Birleşik Krallık'ta yerleşikseniz, Bilgisayarın Kötüye Kullanılması Yasası 1990 kapsamında izin verilmiş sayılır.
  • Bir güvenlik açığını yeniden üretirken meydana gelebilecek kişisel verilerin arızi işlenmesi durumunda, GDPR Madde 6(1)(f) uyarınca meşru amaç (güvenli bir hizmet sunmadaki meşru çıkarlar) kapsamında kabul edilir.
  • Aksi takdirde ileri sürebileceğimiz herhangi bir hizmet şartı ihlali iddiasından muaf tutulur.

"İyi niyet" şu anlama gelir: Güvenlik açığının varlığına dair gerçek bir inancınız olmalı; açığın sömürülebilir olduğunu onaylar onaylamaz testi durdurmalı ve bildirmelisiniz; sorunu göstermek için gereken minimum düzeyin ötesinde müşteri verilerini sızdırmamalı, değiştirmemeli, saklamamalı veya paylaşmamalısınız; ve kamuya açıklamadan önce bize sorunu çözmemiz için makul bir süre tanımalısınız.

Yanıt süreleri

AşamaHedef
Alındı bildirimi1 iş günü
Değerlendirme kararı (kapsam içi / kapsam dışı / mükerrer)2 iş günü
Kritik / Yüksek öncelikli düzeltme14 gün içinde en iyi çaba
Orta / Düşük öncelikli düzeltme60 gün içinde en iyi çaba
Kamuya açıklamaKoordineli; kabul edilen bulguları düzeltme yayına alındıktan sonra yayınlarız

Bir hedefi kaçırırsak, süre dolmadan önce size bir durum güncellemesi göndereceğiz. Bu aşamada hata ödülü (bug bounty) ödemiyoruz ancak size kamuya açık bir şekilde teşekkür edeceğiz (veya isteğinize göre anonim tutacağız). Birden fazla geçerli bildirim yapan araştırmacılar güvenilir raporcu statüsü kazanarak daha hızlı bir iletişim kanalına erişim elde ederler.

Teşekkür ve Atıflar

Burada gerçek bir sorunu bildiren her araştırmacıya teşekkür ederiz. Onur listemiz şu anda boştur — AssurePort Mayıs 2026'da faaliyete geçti ve kamuya açık bildirim geçmişimizin henüz başındayız. Bu politika kapsamında kabul edilen raporlar, tarih, önem derecesi ve hata sınıfının kısa bir açıklamasıyla birlikte aşağıda listelenecektir.

Bir rapor onur listesine nasıl girer?

  • Rapor yukarıdaki tabloya göre kapsam içindedir ve güvenli liman koşulları korunmuştur.
  • Bildiriminizden veya makul bir açıklama aşamasından sonra sorunu yeniden üretebildik.
  • Düzeltme canlı ortama yüklendi. Onur listesi satırı ilgili değişiklik günlüğü (changelog) satırına bağlantı verir.
  • Kamuya açık bir şekilde atıfta bulunulmasını kabul ettiniz. Anonim raporlar da düzeltilir ve kendilerine özel olarak teşekkür edilir; sadece bu tabloda görünmezler.

Kayıt formatı

Her satır; düzeltmenin yayınlandığı tarihi, etkilenen yüzeyi, değerlendirdiğimiz önem seviyesini, tek satırlık hata sınıfı açıklamasını, tercih ettiğiniz atıf adını ve değişiklik günlüğü bağlantısını içerir.

YayınlandıYüzeyÖnemHata SınıfıRaporlayanDeğişiklik Günlüğü
Henüz harici bir rapor kabul edilmedi — ilk kayıt bekleniyor.

Platformun kendi kendine yaptığı sızma testlerinden elde edilen dahili bulgular (Sprint 6 ve sonrası) ayrı olarak yayınlanır — bu tablo yalnızca bu politika kapsamındaki harici araştırmacılara ayrılmıştır.

Yasal dayanak

Bu politika, RFC 9116 kapsamında https://assureport.com/.well-known/security.txt tarafından referans gösterilmektedir. Politikaya uyan iyi niyetli araştırmacılar bakımından AssurePort için bağlayıcıdır. Kapsam dışındaki eylemler için (örneğin hizmet dışı bırakma, diğer müşterilerin verilerine erişme, müşterilere zarar verme) cezai sorumluluğu ortadan kaldırmaz. İstihdam, temsilcilik veya yüklenicilik ilişkisi oluşturmaz.

Son güncelleme: 2026-05-14. Politika revizyonları, halihazırda iyi niyetle devam eden bildirimler için güvenli liman korumasını geriye dönük olarak kaldırmaz.

Sicherheitsrichtlinie zur Offenlegung von Schwachstellen

Wenn Sie glauben, eine Sicherheitslücke in einem System oder Dienst von AssurePort gefunden zu haben, möchten wir von Ihnen hören. Diese Seite ist die offizielle Richtlinien-URL (Policy URL), auf die in /.well-known/security.txt (RFC 9116) verwiesen wird. Bitte lesen Sie diese vor Ihrer Meldung durch.

Sprache: Die englische Version ist der rechtlich verbindliche Originaltext. Die Übersetzungen ins Türkische, Deutsche und Französische dienen lediglich der Information; bei Abweichungen ist die englische Version maßgebend.

Wie man meldet

Senden Sie eine einzelne E-Mail an abuse@assureport.com mit folgenden Angaben:

  • Eine Beschreibung des Problems und seiner Auswirkungen in eigenen Worten.
  • Die genaue URL oder den Endpoint, auf dem das Problem auftritt.
  • Eine Schritt-für-Schritt-Anleitung zur Reproduktion (curl-Befehle, Payloads, Screenshots).
  • Alle für die Reproduktion erforderlichen Konto-, Header- oder Sitzungsdaten – Ihnen entstehen keine Nachteile durch das Mitsenden von Zugangsdaten, die Sie beim Testen verwendet haben.
  • Ihr bevorzugter Name für die Nennung (Danksagung) oder „anonym“.

Bei sensiblen Berichten können Sie auch legal@assureport.com in CC setzen. Berichte, die über X / Twitter / Mastodon DMs eingereicht werden, werden nicht überwacht – nutzen Sie bitte ausschließlich E-Mail.

PGP-Verschlüsselung (optional)

Wenn Ihre Feststellung sensible Daten enthält, die Sie nicht im Klartext senden möchten, verschlüsseln Sie diese mit unserem Offenlegungsschlüssel. Überprüfen Sie den Fingerabdruck außerhalb des Bandes (mindestens zwei von: dieser Seite, der Encryption-Direktive in /.well-known/security.txt, einem signierten Änderungsprotokoll oder einem signierten Blogbeitrag), bevor Sie ihm vertrauen.

Offenlegungsschlüssel (wird jährlich rotiert)

Fingerabdruck: 2026 ASSUREPORT DISCLOSURE — KEY ROTATION PENDING

Status: Die Veröffentlichung ist für die Rotation des Vertrauensankers in Sprint 9 geplant. Bis der ASCII-verschlüsselte Block hier veröffentlicht wird, ist Klartext an abuse@assureport.com akzeptabel – E-Mails werden über TLS übertragen und das Postfach wird vom diensthabenden Sicherheitsteam überwacht.

Im Umfang

OberflächeHinweise
assureport.comMarketing-Oberfläche, freie APIs zur Bedrohungsanalyse, öffentliche Dokumentation.
app.assureport.comKonsole, Mandanten-API, Abrechnungsabläufe.
api.assureport.comÖffentliche und Mandanten-APIs.
Die von uns generierten PDF- / Markdown-BerichteDarstellung der Ergebnisse, Datenabfluss zwischen Mandanten.

Außerhalb des Umfangs

  • Volumetrische Tests oder Denial-of-Service-Tests jeglicher AssurePort-Systeme.
  • Social Engineering von AssurePort-Mitarbeitern, Auftragnehmern oder Partnern (Polar.sh, Cloudflare, Anthropic, Fly.io).
  • Physische Angriffe auf AssurePort-Büros, Mitarbeiter oder Lieferanten.
  • Tests gegen andere Mandanten als Ihren eigenen – einschließlich des „Selbst-Pentest“-Ziels der Plattform. Verwenden Sie das kostenlose Threat-Intel-Toolkit, wenn Sie sich die Marketing-Oberfläche ohne Authentifizierung ansehen möchten.
  • Fehler, die nur in veralteten oder anfälligen Client-Browsern reproduzierbar sind, die wir nicht unterstützen (z. B. Browser, die älter als 24 Monate sind oder TLS 1.2 nicht unterstützen).
  • Fehlende Sicherheits-Header auf reinen Marketing-Seiten, die keine authentifizierten Daten verarbeiten.
  • SPF- / DMARC- / DKIM-Richtliniendetails (uns bekannt; unsere geschäftliche E-Mail-Domain wird streng konfiguriert).

Sicherer Hafen (Safe Harbor)

AssurePort betrachtet in gutem Glauben durchgeführte Sicherheitsforschung im Rahmen dieser Richtlinie als:

  • Autorisierte Handlung im Sinne des Computer Fraud and Abuse Act (CFAA), sofern Sie in den USA ansässig sind.
  • Autorisierte Handlung im Sinne des Computer Misuse Act 1990, sofern Sie im Vereinigten Königreich ansässig sind.
  • Rechtmäßiger Zweck gemäß Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse am Betrieb eines sicheren Dienstes) für die gelegentliche Verarbeitung personenbezogener Daten, die bei der Reproduktion einer Schwachstelle erfolgt.
  • Befreit von jeglichen Ansprüchen wegen Verletzung der Nutzungsbedingungen, die wir andernfalls geltend machen könnten.

„Guter Glaube“ bedeutet: Sie haben einen begründeten Verdacht auf eine Schwachstelle; Sie stoppen die Tests und melden das Problem, sobald Sie die Ausnutzbarkeit bestätigt haben; Sie kopieren, ändern, speichern oder teilen keine Kundendaten über das für den Nachweis erforderliche Minimum hinaus; und Sie geben uns angemessene Zeit zur Behebung vor einer Veröffentlichung.

Reaktionszeiten

PhaseZiel
Empfangsbestätigung1 Werktag
Triage-Entscheidung (im Umfang / außerhalb des Umfangs / Duplikat)2 Werktage
Behebung (Kritisch / Hoch)Bestmögliche Anstrengung innerhalb von 14 Tagen
Behebung (Mittel / Niedrig)Bestmögliche Anstrengung innerhalb von 60 Tagen
VeröffentlichungKoordiniert; wir veröffentlichen akzeptierte Schwachstellen erst nach Bereitstellung des Fixes

Wenn wir ein Ziel verpassen sollten, informieren wir Sie vor Ablauf der Frist über den aktuellen Stand. Wir zahlen in dieser Phase keine Bug Bounties, nennen Sie jedoch gerne namentlich in unserer Danksagung (oder halten Sie anonym, ganz wie Sie möchten). Forscher mit wiederholt validen Meldungen erhalten den Status eines vertrauenswürdigen Reporters und einen schnelleren Kommunikationskanal.

Danksagungen

Wir danken jedem Forscher, der hier ein echtes Problem meldet. Die Hall of Fame is derzeit leer – AssurePort wurde im Mai 2026 gestartet und wir stehen noch am Anfang. Berichte, die im Rahmen dieser Richtlinie akzeptiert werden, werden unten mit Datum, Schweregrad und einer kurzen Beschreibung der Problemklasse aufgeführt.

Wie ein Bericht in die Liste aufgenommen wird

  • Die Meldung liegt im Rahmen der obigen Tabelle und die Bedingungen für den sicheren Hafen wurden eingehalten.
  • Wir konnten das Problem anhand Ihrer Beschreibung oder nach einer kurzen Rückfrage reproduzieren.
  • Ein Fix wurde in der Produktion bereitgestellt. Der Eintrag verweist auf die Zeile im Änderungsprotokoll (Changelog).
  • Sie haben einer öffentlichen Nennung zugestimmt. Anonyme Berichte werden ebenfalls behoben und erhalten ein privates Dankeschön; sie erscheinen nur nicht in dieser Tabelle.

Eintragsformat

Jede Zeile enthält das Datum der Bereitstellung des Fixes, die betroffene Oberfläche, die von uns eingestufte Schweregradstufe, eine einzeilige Beschreibung der Fehlerklasse, Ihren bevorzugten Namen für die Nennung und den Link zum Änderungsprotokoll.

BereitgestelltOberflächeSchweregradKlasseReporterChangelog
Noch keine externen Berichte akzeptiert – erster Eintrag ausstehend.

Interne Erkenntnisse aus dem Selbst-Pentest der Plattform (ab Sprint 6) werden separat veröffentlicht – diese Tabelle ist externen Forschern im Rahmen dieser Richtlinie vorbehalten.

Rechtsgrundlage

Diese Richtlinie wird von https://assureport.com/.well-known/security.txt gemäß RFC 9116 referenziert. Sie ist für AssurePort gegenüber Forschern, die in gutem Glauben handeln und sich an sie halten, bindend. Sie schließt keine strafrechtliche Haftung für Handlungen außerhalb ihres Umfangs aus (z. B. Denial-of-Service, Zugriff auf Daten anderer Mandanten, Schädigung von Kunden). Es entsteht dadurch kein Arbeits-, Vertretungs- oder Auftragsverhältnis.

Zuletzt aktualisiert am 14.05.2026. Richtlinienänderungen entziehen bereits in gutem Glauben laufenden Meldungen nicht rückwirkend den Schutz des sicheren Hafens.

Politique de divulgation de sécurité

Si vous pensez avoir découvert une vulnérabilité de sécurité dans un système ou service d'AssurePort, nous vous invitons à nous le signaler. Cette page est l'URL officielle de la politique (Policy URL) référencée par /.well-known/security.txt (RFC 9116). Veuillez la lire avant de soumettre un rapport.

Langue : La version anglaise est le texte juridique officiel et fait foi. Les traductions en turc, allemand et français sont fournies uniquement à des fins d'information ; en cas de conflit, la version anglaise prévaut.

Comment signaler

Envoyez un e-mail unique à abuse@assureport.com contenant les informations suivantes :

  • Une description du problème et de son impact dans vos propres mots.
  • L'URL exacte ou le point d'accès (endpoint) concerné.
  • Les instructions étape par étape pour reproduire la vulnérabilité (commandes curl, payloads, captures d'écran).
  • Les données de compte, d'en-tête ou de session nécessaires à la reproduction – vous ne serez pas pénalisé pour avoir fourni des identifiants utilisés lors de vos tests.
  • Le nom ou pseudonyme que vous souhaitez voir apparaître pour l'attribution, ou la mention « anonyme ».

Pour les rapports particulièrement sensibles, vous pouvez également mettre legal@assureport.com en copie. Les rapports envoyés via les messages privés X / Twitter / Mastodon n'étant pas surveillés, veuillez utiliser uniquement l'e-mail.

Chiffrement PGP (optionnel)

Si vos conclusions contiennent des informations sensibles que vous préférez ne pas envoyer en clair, chiffrez-les avec notre clé de divulgation. Vérifiez l'empreinte de la clé de manière indépendante (au moins deux sources parmi : cette page, la directive Encryption dans /.well-known/security.txt, une entrée de changelog signée ou un article de blog signé) avant de lui faire confiance.

Clé de divulgation (renouvelée annuellement)

Empreinte : 2026 ASSUREPORT DISCLOSURE — KEY ROTATION PENDING

Statut : La publication est planifiée pour la rotation des ancres de confiance lors du Sprint 9. En attendant la publication du bloc ASCII ici, l'envoi en clair à abuse@assureport.com est accepté – les e-mails sont acheminés via TLS et la boîte de réception est surveillée par l'équipe de sécurité de garde.

Dans le périmètre

SurfaceRemarques
assureport.comSurface marketing, APIs gratuites d'intelligence des menaces, documentation publique.
app.assureport.comConsole, API client, flux de facturation.
api.assureport.comAPIs publiques et clients.
Les rapports PDF / Markdown générés par la plateformeRendu des conclusions, fuite de données entre clients.

Hors périmètre

  • Les tests volumétriques ou de déni de service (DoS/DDoS) sur toute infrastructure d'AssurePort.
  • L'ingénierie sociale visant le personnel, les sous-traitants ou les prestataires d'AssurePort (Polar.sh, Cloudflare, Anthropic, Fly.io).
  • Les attaques physiques contre les bureaux, employés ou fournisseurs d'AssurePort.
  • Les tests ciblant des clients autres que le vôtre – y compris la cible d'auto-test d'intrusion de la plateforme. Utilisez les outils d'intelligence gratuits si vous souhaitez analyser la surface marketing sans authentification.
  • Les failles uniquement reproductibles sur des navigateurs clients obsolètes ou vulnérables que nous ne prenons pas en charge (ex. navigateurs de plus de 24 mois ou sans support de TLS 1.2).
  • L'absence d'en-têtes de sécurité sur la surface marketing pure ne traitant pas de données authentifiées.
  • Les remarques de configuration SPF / DMARC / DKIM (nous en sommes conscients ; notre domaine de messagerie d'entreprise utilise des règles strictes).

Sphère de sécurité (Safe Harbor)

AssurePort considère que toute recherche de sécurité de bonne foi effectuée conformément à cette politique est :

  • Autorisée en vertu du Computer Fraud and Abuse Act (CFAA), si vous résidez aux États-Unis.
  • Autorisée en vertu du Computer Misuse Act 1990, si vous résidez au Royaume-Uni.
  • Poursuivie pour un motif légitime au titre de l'article 6(1)(f) du RGPD (intérêts légitimes liés à l'exploitation d'un service sécurisé) pour tout traitement accidentel de données personnelles survenant lors de la reproduction d'une vulnérabilité.
  • Exempte de toute plainte pour violation des conditions d'utilisation que nous pourrions autrement formuler.

La « bonne foi » implique que : vous croyez sincèrement en la vulnérabilité ; vous cessez les tests et signalez le problème dès que vous confirmez l'exploitabilité ; vous n'exfiltrez, ne modifiez, ne conservez ni ne partagez aucune donnée client au-delà du strict minimum requis pour faire la démonstration ; et vous nous accordez un délai raisonnable pour résoudre le problème avant toute divulgation publique.

Délais de réponse

ÉtapeObjectif
Accusé de réception1 jour ouvrable
Décision de tri (dans le périmètre / hors périmètre / doublon)2 jours ouvrables
Résolution (Critique / Élevé)Meilleurs efforts sous 14 jours
Résolution (Moyen / Faible)Meilleurs efforts sous 60 jours
Divulgation publiqueCoordonnée ; nous publions les rapports acceptés après le déploiement du correctif

Si nous manquons un objectif, nous vous en informerons avant l'échéance. Nous ne versons pas de primes de correction (bug bounties) à ce stade, mais nous vous remercierons publiquement (ou préserverons votre anonymat, selon votre choix). Les rapporteurs réguliers de failles valides obtiennent le statut de rapporteur de confiance et bénéficient d'un canal de communication prioritaire.

Remerciements

Nous remercions tous les chercheurs qui nous signalent des problèmes réels. Le tableau d'honneur est actuellement vide – AssurePort a été lancé en mai 2026 et nous débutons notre historique de divulgation publique. Les rapports acceptés au titre de cette politique seront listés ci-dessous avec leur date, leur sévérité et une brève description de la classe d'erreur.

Comment figurer sur le tableau d'honneur

  • Le rapport entre dans le périmètre défini par le tableau ci-dessus, et les conditions de la sphère de sécurité ont été respectées.
  • Nous avons pu reproduire la faille à partir de vos explications ou après un échange de clarification.
  • Un correctif a été déployé en production. L'entrée de la table renvoie vers la ligne correspondante du journal des modifications (changelog).
  • Vous avez consenti à une attribution publique. Les rapports anonymes sont également corrigés et font l'objet de remerciements privés, mais ne figurent pas dans ce tableau.

Format de publication

Chaque ligne indique la date de déploiement du correctif, la surface concernée, la sévérité attribuée lors du tri, une brève description de la classe d'erreur, le nom d'attribution choisi et le lien vers le journal des modifications.

DéploiementSurfaceSévéritéClasseRapporteurChangelog
Aucun rapport externe accepté pour le moment – première publication en attente.

Les conclusions internes issues des auto-tests d'intrusion de la plateforme (à partir du Sprint 6) sont publiées séparément – cette table est réservée aux chercheurs externes agissant sous cette politique.

Base juridique

Cette politique est référencée par https://assureport.com/.well-known/security.txt conformément à la RFC 9116. Elle engage AssurePort envers les chercheurs agissant de bonne foi et respectant ses termes. Elle ne supprime pas la responsabilité pénale en cas d'actions hors périmètre (ex. déni de service, accès aux données d'autres clients, préjudice causé aux utilisateurs). Elle ne crée aucune relation d'emploi, de mandat ou de sous-traitance.

Dernière mise à jour le 14/05/2026. Les révisions futures de cette politique ne supprimeront pas rétroactivement la protection de la sphère de sécurité pour les rapports déjà en cours de bonne foi.