Legal

Vulnerability disclosure policy

We welcome good-faith security research on the product and this website. This page explains how to report, what is in scope, and how we respond.

Template status: draft template, not yet reviewed

This page is a template. Items marked [Legal review required] must be completed and approved by legal counsel before this site goes to production.

1. How to report

Send reports to CONFIRM-EMAIL@example.com or use the contact form with the Security topic. Include the affected component and version, steps to reproduce, and impact. Please keep exploit details out of the first message and wait for a secure channel if the issue is severe. [Legal review required: PGP key or secure intake channel]

2. Scope

In scope: the Access Witness Dashboard, Collector, installer and update packages, our licensing and update service and this website. Out of scope: Microsoft 365 services themselves (report those to Microsoft), customer deployments you are not authorized to test, denial of service, social engineering and physical attacks.

3. Rules of engagement

Test only against systems you own or are authorized to test. Do not access, modify or exfiltrate data that is not yours. Stop and report as soon as you have demonstrated the issue. We will not pursue legal action against researchers who follow this policy in good faith. [Legal review required: safe-harbor language for the applicable jurisdiction]

4. What to expect

We acknowledge reports within [Legal review required: acknowledgement target], keep you informed while we investigate, and agree a disclosure timeline with you once a fix is available. We credit reporters who want to be credited. [Legal review required: state whether a bounty program exists; do not imply one otherwise]

5. Customer-hosted deployments

Because Private Edition runs in customer infrastructure, a vulnerability report may involve a customer environment. We coordinate with the affected customer and never ask researchers to share customer permission data with us.