🔐 Responsible Disclosure Policy
Last Updated: [SIGNING DATE]
1. Our Commitment
Knox Security ("we", "our", or "us") values the work of independent security researchers in helping us keep our OSINT/threat-intelligence platform and our customers' data safe. This policy describes how to report a suspected security vulnerability to us and what you can expect from that process.
2. Scope
In scope
- breachvision.net and all subdomains
- The Knox Security web application and public API endpoints
- Infrastructure directly operated by Knox Security in support of the above (excludes third-party subprocessors listed at our Trust Center, which have their own disclosure channels)
Out of scope
- Denial-of-service testing
- Social engineering of Knox Security staff or customers
- Physical security testing
- Automated scanning that generates excessive traffic without prior coordination
- Findings requiring physical access to a user's device
- [ADDITIONAL EXCLUSIONS, e.g. third-party integrations, staging environments — list as applicable]
3. How to Report
Email: [email protected]
Subject line: Security Disclosure: [brief description]
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept code or requests
- The URL(s) or endpoint(s) affected
- Your contact information (for follow-up and, if desired, credit)
If you need to encrypt your report, request our PGP key at the address above before sending sensitive details. [PGP KEY FINGERPRINT / LINK, IF AVAILABLE]
4. What to Expect From Us
- Acknowledgment of your report within [X] business days (target: 2 business days)
- An initial assessment and severity triage within [X] business days
- Regular status updates for the duration of remediation
- Notification when the issue is resolved
- Public credit in a security acknowledgments page, if you want it and once a fix has shipped [PAGE URL, IF ONE IS BUILT]
We do not currently operate a paid bug bounty program. [UPDATE IF THIS CHANGES]
5. Safe Harbor
If you make a good-faith effort to comply with this policy while researching or reporting a vulnerability, we will not pursue legal action against you for that research, and we will consider your activity authorized under any applicable "unauthorized access" laws, including the Computer Fraud and Abuse Act (or equivalent laws in [JURISDICTION]), for that purpose. This safe harbor applies only to activity that:
- Stays within the scope defined above
- Does not access, modify, or exfiltrate more data than necessary to demonstrate the vulnerability
- Does not degrade the availability or integrity of our services for other users
- Is reported to us promptly and not disclosed publicly before we've had a reasonable opportunity to remediate (coordinated disclosure window: [X] days, default 90)
If a third party initiates legal action related to activity conducted in good-faith compliance with this policy, we will make it known that your actions were authorized.
6. Contact
This policy may be updated from time to time. The version in effect at the time of your report governs that report.