Vulnerability Disclosure Policy - Own

Vulnerability Disclosure Policy

Version 1.0

Purpose

The purpose of this document is to establish the policy for reporting security vulnerabilities of Own and managed assets. This policy provides security researchers guidelines to conduct ethical research and collaboration of discovered security vulnerabilities of Own.

Program Rules

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct, and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Out of Scope Vulnerabilities

How to Report a Vulnerability

We accept and communicate about potential security vulnerability reports via own.vdp@owndata.com.

We will acknowledge receipt of your report within three business days.

What we would like to see from you

To help us triage and remediate potential findings, a good vulnerability report should:

The Own security team commitment:

We ask that you do not share or publicize an unresolved vulnerability with/to third parties. If you responsibly submit a vulnerability report, the Own security team and associated development organizations will use reasonable efforts to:

We are happy to thank every individual researcher who submits a vulnerability report helping us improve our overall security posture at Own.