Vulnerability Disclosure Program
Template text. This page is placeholder wording supplied with the build. It is not legal advice and must be reviewed and replaced by counsel before launch.
Fortis Business Center welcomes reports of security vulnerabilities in our websites and applications. This page explains how to report one and what to expect in return.
Scope
This programme covers the Fortis Business Center public website, the member portal, and the Fortis app. Third-party services that Fortis Business Center does not operate are out of scope.
How to report
Send a description of the issue, the steps to reproduce it, and its likely impact to the contact address below.
What we ask
Give us reasonable time to investigate and fix the issue before disclosing it publicly. Do not access, modify, or delete data that is not yours, and do not run tests that degrade the service for members.
What you can expect
We acknowledge reports within three business days, keep you updated while we investigate, and credit reporters who ask to be credited once a fix has shipped.
Safe harbour
We will not pursue action against researchers who follow this policy in good faith.
Contact
Questions about this page can be sent to hello@fortisbc.example.