Vulnerability Disclosure Policy
At Curbfind, we consider the security of our systems and our users' data to be of paramount importance. We welcome the contribution of the security research community and encourage the responsible disclosure of any potential vulnerabilities in our services.
Scope
This policy applies to all Curbfind web properties and services, specifically including:
*.curbfind.ca- Our official API endpoints
Safe Harbor
When conducting vulnerability research according to this policy, we consider this research to be authorized. We will not initiate or support legal action against you for accidental, good-faith violations of this policy. We will work with you to understand and resolve the issue quickly.
Reporting Guidelines
If you believe you have found a security vulnerability, please submit your report to security@curbfind.ca. Please include:
- A description of the vulnerability and its potential impact.
- Detailed steps to reproduce the vulnerability (including any necessary scripts or payloads).
- Any relevant screenshots or logs.
Our Commitment
- We will acknowledge receipt of your report within 3 business days.
- We will provide an estimated timeframe for addressing the vulnerability.
- We will notify you when the vulnerability has been patched.
Rules of Engagement
- Do not perform attacks that could harm the reliability or integrity of our services or data (e.g., DoS, DDoS).
- Do not interact with other users' accounts or data without their explicit consent.
- Do not publicly disclose the vulnerability until we have had reasonable time to resolve the issue (typically 90 days).