Last updated: April 14, 2025
At Unframe, we take the security of our systems seriously. We value the contributions of the security community and welcome reports from ethical hackers and researchers who help us keep our users safe.
β
This Responsible Disclosure Policy (the "Policy") outlines how to report potential security vulnerabilities to Unframe and what you can expect from us in return.
β
By submitting a vulnerability report to Unframe, you acknowledge that you have read, understood, and agree to abide by this Policy. Unframe will not pursue legal action against individuals who discover and report vulnerabilities in accordance with these guidelines.
β
If you have discovered a potential security vulnerability, we encourage you to report it to us responsibly.
β
Scope
β
This policy applies to:
Guidelines for Responsible Disclosure
β
To protect our users and systems, we ask you:
What You Can Expect from Us
β
Out of Scope Vulnerabilities
β
The following are typically not considered in scope unless they present a clear security risk:
How to Report
β
Once you locate a vulnerability, please report it to our security team by sending your report to: cybersecurity@unframe.ai. Please include a detailed explanation of how the vulnerability was found, including reproducible steps, and clear evidence (such as screenshots, video, or command lines).
β
Once your report has been submitted, our security team will reach back [within ___ days] and acknowledge that they have received the report. If needed, they may request additional information, or clarifications. When the investigation process of the reported vulnerability has been concluded, our security team will reach out communicate any appropriate information and details on the investigation and vulnerability back to you, and to any other relevant parties. Β
β
Confidentiality Requirements
β
Any information you receive or collect about Unframe, its systems, clients, or employees during your security research must be kept strictly confidential. This includes:
You may not use, disclose, or distribute any confidential information without prior written consent from Unframe. This confidentiality requirement extends beyond the resolution of any reported vulnerability.
β
We expect all security researchers to destroy any collected data or information once the vulnerability has been reported and resolved.
β
Legal Safe Harbor
β
To encourage good-faith security research, Unframe commits that we will not initiate legal action for security research conducted in good faith compliance with this policy.
This safe harbor is strictly conditional upon:
Miscellaneous
β
Unframe reserves the right to amend this Policy at any time. Changes will be posted to our website with an updated effective date. Continued participation in our vulnerability disclosure program following such changes constitutes acceptance of the revised Policy.
β
Unframe reserves all legal rights for activities conducted outside this policy's guidelines.
If in doubt, please contact us first.
β