Responsible Disclosure Policy
Last updated: January 2025
Guidelines for security researchers to report vulnerabilities in a safe, coordinated manner.
TL;DR
- •We welcome responsible security research and vulnerability reports
- •Report vulnerabilities privately to weare@modernancients.com
- •Allow us time to fix issues before public disclosure
- •We will acknowledge reports within 48 hours and provide updates
- •We recognize and may reward researchers who follow this policy
- •Do not access or modify data that does not belong to you
1. Our Commitment
SOVEREIGN\PROVENANCE values the security research community. We recognize that responsible disclosure helps protect our users and the integrity of the provenance ecosystem.
This policy outlines how to report security vulnerabilities safely and how we will respond. By following these guidelines, you help us maintain a secure platform while protecting yourself from legal risk.
2. Scope: What We Want to Know About
We encourage reports of security vulnerabilities in:
- Web applications and APIs
- Authentication and authorization systems
- Data encryption and storage
- Provenance integrity mechanisms
- Infrastructure and network security
- Third-party integrations
Out of scope: Social engineering, physical security, denial-of-service attacks, spam, or issues requiring physical access to systems.
3. How to Report
Please send vulnerability reports to weare@modernancients.com with the following information:
- Description of the vulnerability
- Steps to reproduce (proof-of-concept code or screenshots if helpful)
- Potential impact and severity assessment
- Suggested remediation (if you have ideas)
- Your contact information (for follow-up questions)
If you prefer encrypted communication, please use PGP. Our public key is available upon request.
4. What We Promise
When you report a vulnerability responsibly, we commit to:
- Timely Response: Acknowledge receipt within 48 hours
- Regular Updates: Provide status updates at least every 14 days
- Fair Assessment: Evaluate the vulnerability promptly and honestly
- Coordination: Work with you to understand and fix the issue
- Recognition: Credit you in our security advisories (if you wish)
- No Legal Action: We will not pursue legal action against researchers who follow this policy
5. What We Ask of You
To qualify for protection under this policy, please:
- Report Privately: Do not disclose the vulnerability publicly until we have fixed it
- Act in Good Faith: Do not access or modify data that does not belong to you
- Minimize Impact: Avoid actions that could harm users or system availability
- Respect Privacy: Do not access, download, or share user data
- Give Us Time: Allow at least 90 days for remediation before public disclosure
- Follow the Law: Comply with all applicable laws and regulations
6. Safe Harbor
If you act in good faith and follow this Responsible Disclosure Policy, we will not pursue legal action against you for security research activities, even if they might otherwise violate our Terms of Service or Acceptable Use Policy.
This safe harbor applies only if:
- You report the vulnerability privately to weare@modernancients.com
- You do not access, modify, or delete data that does not belong to you
- You do not disrupt or degrade our services
- You do not violate any laws
- You give us reasonable time to fix the issue before public disclosure
7. Bug Bounty Program
We may offer monetary rewards or other recognition for particularly significant vulnerabilities, at our discretion. Rewards are based on:
- Severity and impact of the vulnerability
- Quality of the report
- Compliance with this policy
Participation in any bug bounty program is subject to separate terms and conditions. Not all vulnerabilities will receive monetary rewards.
8. Disclosure Timeline
Our typical disclosure process:
- Day 0: You report the vulnerability
- Day 1-2: We acknowledge receipt
- Day 3-30: We investigate and develop a fix
- Day 31-60: We test and deploy the fix
- Day 61-90: We coordinate public disclosure (if appropriate)
Complex vulnerabilities may take longer. We will keep you informed of progress.
9. What Not to Do
Activities that are not covered by this policy and may result in legal action:
- Accessing accounts or data that do not belong to you
- Modifying or deleting user data
- Disrupting or degrading service availability
- Publicly disclosing vulnerabilities before we have fixed them
- Demanding payment as a condition of disclosure
- Using vulnerabilities for personal gain
- Violating any applicable laws
10. Questions
If you have questions about this policy or need clarification on whether a particular activity is permitted, please contact us at weare@modernancients.com before proceeding.