{"id":13569,"date":"2025-06-18T12:35:00","date_gmt":"2025-06-18T07:05:00","guid":{"rendered":"https:\/\/addverb.com\/us\/?page_id=13569"},"modified":"2026-01-09T15:46:44","modified_gmt":"2026-01-09T10:16:44","slug":"responsible-disclosure-policy","status":"publish","type":"page","link":"https:\/\/addverb.com\/us\/responsible-disclosure-policy\/","title":{"rendered":"Responsible Disclosure Policy"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h1 class=\"wp-block-heading has-text-align-center\">RESPONSIBLE DISCLOSURE POLICY<\/h1>\n\n\n\n<p><strong>Effective Date: <\/strong><strong>18 June 2025<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>Last Updated: 18 June 2025<\/strong>&nbsp;<\/p>\n\n\n\n<p>At Addverb Technologies Private Limited, including its subsidiaries (\u201cAddverb\u201d), we take security seriously. We recognize the valuable role that independent Security Researchers play in helping us maintain the highest standards of cybersecurity. This Responsible Disclosure Policy (\u201cPolicy\u201d) outlines the process by which Security Researchers can report potential security vulnerabilities in Addverb\u2019s digital assets in a lawful, responsible and ethical manner.&nbsp;<\/p>\n\n\n\n<p>By following this Policy, Security Researchers can contribute to the overall safety and resilience of our systems; while ensuring they remain protected from legal action, provided they strictly adhere to the terms set out herein.&nbsp;<\/p>\n\n\n\n<p><strong>Scope of Policy<\/strong>&nbsp;<\/p>\n\n\n\n<p>This policy applies to addverb.com and its subdomains, operated, or managed by Addverb that are explicitly covered under public-facing domains.&nbsp;<\/p>\n\n\n\n<p>This Policy does not authorize:&nbsp;<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Any access to systems beyond the intended scope.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>Testing on non-public or third-party assets.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>Violation of applicable laws.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>For the purpose of this Policy, \u201cSecurity Researcher\u201d means any individual or entity who, in good faith, interacts with Addverb\u2019s systems, services, or products for the sole purpose of reporting a security vulnerability in accordance with this Policy. This includes ethical hackers, independent researchers, bug bounty hunters, and any other parties submitting such reports.&nbsp;<\/p>\n\n\n\n<p><strong>Responsible Disclosure Process<\/strong>&nbsp;<\/p>\n\n\n\n<p>We ask that all Security Researchers:&nbsp;<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Act in good faith and within the bounds of the law.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>Avoid any actions that could cause harm, disruption, or loss to Addverb or its customers.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>Provide a detailed report, including steps to reproduce the issue, potential impact, and recommended remediation.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li>Do not disclose the vulnerability to the public or any third party until Addverb provides express written permission, in advance.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p><strong>Reporting<\/strong>&nbsp;<\/p>\n\n\n\n<p>To report a vulnerability, please email us at <strong>infosec@addverb.com<\/strong>&nbsp;<\/p>\n\n\n\n<p>Your report should include:&nbsp;<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>A clear description of the vulnerability.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>The date and time of discovery.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>Assumed Impact&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li>Affected services, or URLs.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li>Step-by-step instructions to reproduce the issue.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"6\" class=\"wp-block-list\">\n<li>Any relevant screenshots, logs, or proof-of-concept code.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"7\" class=\"wp-block-list\">\n<li>Recommended Fix&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>Addverb will acknowledge receipt within 7 business days and aim to assess and resolve valid issues within a technically reasonable timeframe. Addverb may choose to disregard submissions by parties who submit a high volume of low-quality reports.&nbsp;<\/p>\n\n\n\n<p><strong>Exclusions<\/strong>&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vulnerabilities that do not demonstrate security impact will be considered out of scope for this program.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vulnerabilities regarding SPF\/DMARC\/DKIM records without verifiable proof of spoofing&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Best practice concerns like non-session cookies not marked secure and HTTP only, SSL\/TLS configuration, missing security headers, etc.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vulnerabilities reported by automated tools and scanners without additional proof of concept&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Spam, brute-force attacks, or testing involving personal data.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Exploits that need physical access to the victim\u2019s device&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Host header injection&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Previously known vulnerable libraries without a working Proof of Concept&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Any kind of spoofing attacks or any attacks that lead to phishing (e.g. Email spoofing, Capturing login credentials with fake login page)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Bugs requiring exceedingly unlikely user interaction i.e., social engineering attacks, both against users and Addverb employees, in particular.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Third-party API key disclosures without any impact or which are supposed to be open\/public. Specifically, exposed Google Map API keys and keys in Android XML files.&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OPTIONS \/ TRACE HTTP methods enabled&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Known public files or directories disclosure (e.g. robots.txt, CSS\/images, etc)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Presence of application or web browser \u2018autocomplete\u2019 or \u2018save password\u2019 functionality&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Any kind of vulnerabilities that require installation of software like web browser add-ons, etc. in the victim&#8217;s machine&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Brute force on forms (e.g. Newsletter \/ ContactUs page)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Missing best practices in Content Security Policy.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Missing SSL, CAA headers&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Functional, UI, and UX bugs and spelling mistakes.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Violations of the exclusions listed above may result in disqualification from safe harbour protections and potential legal action.&nbsp;<\/p>\n\n\n\n<p><strong>No Rewards<\/strong>&nbsp;<\/p>\n\n\n\n<p>No monetary compensation is offered or provided in connection with reporting vulnerabilities. This policy is not intended to encourage or authorize penetration testing, scanning, or hacking attempts against Addverb\u2019s information technology infrastructure, but rather to provide a responsible and secure framework under which legitimate security vulnerability disclosures can be communicated and remediated.&nbsp;<\/p>\n\n\n\n<p>Addverb reserves the right to assess each submission on a case-to-case basis. At its sole discretion, Addverb may choose to provide non-monetary gestures of appreciation, such as public acknowledgement or a letter of recognition, subject to a mutual agreement and only where the Security Researcher has complied with all terms of this Policy.&nbsp;<\/p>\n\n\n\n<p><strong>Points to Remember<\/strong>&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do not exploit any vulnerability beyond what is necessary to prove its existence.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do not access, copy, download, or tamper with data that does not belong to you.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do not disrupt any system or service availability during testing.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Do not attempt to gain access to accounts or credentials of other users.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>All activity must remain within the scope and limits set out in this Policy.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><strong>Indemnity<\/strong>&nbsp;<\/p>\n\n\n\n<p>By submitting a vulnerability report under this Policy, the Security Researcher agrees to indemnify, defend, and hold harmless Addverb, its affiliates, officers, directors, employees, and agents from and against any and all claims, damages, liabilities, losses, costs, and expenses (including attorney\u2019s fees) arising out of or related to the Security Researcher\u2019s conduct, actions, or omissions that breach the terms of this Policy, violate applicable laws, or cause harm to Addverb or any third party.&nbsp;<\/p>\n\n\n\n<p><strong>Legal Notice and Disclaimer<\/strong>&nbsp;<\/p>\n\n\n\n<p>Addverb reserves all legal rights in the event of any non-compliance with this Policy, including rights to initiate criminal or civil proceedings under applicable laws and relevant international legislation.&nbsp;<\/p>\n\n\n\n<p>This policy does not grant any license (express or implied) to access Addverb\u2019s systems or to perform security testing. Addverb reserves the right to modify or withdraw this Policy at any time without notice. Participation does not create any contractual relationship between Addverb and Security Researcher.&nbsp;<\/p>\n\n\n\n<p><strong>Contact Us<\/strong>&nbsp;<\/p>\n\n\n\n<p>All questions, comments, or vulnerability reports under this Policy should be directed to <strong>infosec@addverb.com<\/strong>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>RESPONSIBLE DISCLOSURE POLICY Effective Date: 18 June 2025&nbsp; Last Updated: 18 June 2025&nbsp; At Addverb Technologies Private Limited, including its subsidiaries (\u201cAddverb\u201d), we take security seriously. We recognize the valuable &#8230;<\/p>\n","protected":false},"author":8,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"privacy-policy.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-13569","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/pages\/13569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/comments?post=13569"}],"version-history":[{"count":0,"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/pages\/13569\/revisions"}],"wp:attachment":[{"href":"https:\/\/addverb.com\/us\/wp-json\/wp\/v2\/media?parent=13569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}