Responsible Disclosure Policy
Effective Date:
Last Updated:
BaseDynamics Inc. ("BaseDynamics," "We," "Us") values the work of independent security researchers in helping us keep our customers' data safe. This policy describes how to report a suspected security vulnerability to us and what you can expect in return.
Our Commitment
If you report a vulnerability in accordance with this policy, We will:
- Acknowledge receipt of your report in a timely manner;
- Investigate the report in good faith and keep you reasonably informed of our progress;
- Not pursue civil or criminal legal action, or refer you to law enforcement, for good-faith research conducted in accordance with this policy; and
- Recognize your contribution, if you would like us to, once the issue is resolved.
Scope
In scope:
- The BaseDynamics website at basedynamics.com
- The BaseDynamics web application and its subdomains (e.g., *.basedynamics.com)
- BaseDynamics-hosted OAuth integration endpoints for connected accounts (e.g., Gmail/Google Workspace, Microsoft 365), to the extent hosted on BaseDynamics infrastructure
Out of scope:
- Third-party infrastructure or services we rely on (e.g., AWS, Microsoft Azure, OpenAI, Anthropic, Temporal Cloud, Google, Microsoft 365, payment processors), please report these directly to the relevant vendor
- Customer-specific or customer-configured environments
- Social engineering, phishing, or physical attacks against BaseDynamics staff or facilities
- Denial-of-service (DoS/DDoS) attacks or testing
- Automated scanning that generates significant traffic without prior coordination with us
- Issues with no demonstrable security impact, including but not limited to: missing security headers or cookie flags without proven impact, SPF/DKIM/DMARC findings, clickjacking without proven impact, self-XSS, open redirects without proven impact, rate-limiting or account-lockout policy suggestions, and UI/UX or spelling issues
- Reports without a working proof of concept or reasonable evidence of exploitability
Rules of Engagement
When testing for or reporting a vulnerability, you agree to:
- Stay within the defined scope.
- Avoid privacy violations, data destruction, or degradation/interruption of our services.
- Only interact with test accounts you own or have explicit permission to use. Never access, modify, or exfiltrate another user's data.
- Give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly, and keep details of any valid vulnerability confidential until we confirm it has been resolved.
- Not use findings for any purpose other than reporting them to us (e.g., no extortion, no unauthorized disclosure, no further exploitation).
Reports that do not comply with these rules may not be eligible for the protections described in "Our Commitment" above.
How to Report
Please send reports to security@basedynamics.com with as much of the following detail as possible:
- Your name and a way to contact you
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any supporting evidence (e.g., screenshots, request/response logs, proof-of-concept code)
Please do not include real customer data in your report; use test data wherever possible.
Compensation
BaseDynamics does not currently operate a paid bug bounty program and does not guarantee monetary compensation for vulnerability reports. At its sole discretion, BaseDynamics may choose to send a token of appreciation (e.g., swag) for valid, high-quality reports. Requesting payment as a condition of disclosure is inconsistent with this policy.
Public Disclosure
This program operates under a coordinated (non-public) disclosure model. Please do not publicly disclose details of a reported vulnerability, including on social media, blogs, or security mailing lists, without our prior written agreement on timing and content.
Questions
If you have questions about this policy, please contact security@basedynamics.com. We may update this policy from time to time; the "Effective Date" above reflects the most recent revision.