Vulnerability Disclosure Policy

Version 1.1 —

Introduction

We are committed to protecting users' information and ensuring the security of our systems. This policy provides guidelines for security researchers to responsibly conduct vulnerability discovery and report findings to us.

This document outlines: what systems are in scope, what testing is authorized, how to submit reports securely, and how long to wait before public disclosure.

Authorization & Safe Harbor

If you make a good faith effort to comply with this policy, your research is authorized. We will not pursue or recommend legal action, and we will not consider your activities a violation of our Terms of Service, the Computer Fraud and Abuse Act (CFAA), the DMCA, or similar laws. If a third party initiates legal action for activities conducted under this policy, we will make this authorization known.

Guidelines for Research

Prohibited Testing

Scope

This policy applies to the primary website of the domain where this policy is published and its immediate subdomains, unless explicitly excluded.

Out of scope: staging/test environments; vendor-managed systems; services not expressly listed as in scope; vulnerabilities in third-party providers (report directly to the vendor).

If unsure whether a system is in scope, contact security@7thcircledesigns.com before testing.

Out of Scope Findings (Won't Be Accepted)

Reporting a Vulnerability

Send reports to: disclosure@pm.7thcircledesigns.com

Anonymous submissions are allowed. If you provide contact information, we will acknowledge receipt within 3 business days.

By submitting a vulnerability, you acknowledge that no monetary compensation is offered and you waive any future payment claims related to your submission.

Secure Submission

For encrypted communication, use our PGP key and security.txt published at:

What We'd Like to See from You

What You Can Expect from Us

Recognition

While we do not offer monetary rewards, researchers who responsibly disclose valid vulnerabilities may, with permission, be recognized on a Hall of Fame page.

Questions

Questions or suggestions about this policy: security@7thcircledesigns.com

Document Change History

Version Date Description
1.1 Added Safe Harbor; clarified scope, 90-day disclosure timeline, out-of-scope items; added encrypted submission references.
1.0 First issuance.