
Security Disclosure
Responsible Disclosure & Vulnerability Reporting Policy
Last Updated: January 2026
1. Our Commitment to Security
At SECUSYSTS TECHNOLOGIES Inc. ("SECUSYSTS," "we," "us," or "our"), security is foundational to everything we do. As a cybersecurity and managed security services provider, we take vulnerabilities seriously and value responsible, good-faith security research.
This Security Disclosure page explains how to responsibly report security vulnerabilities and outlines the rules, expectations, and protections that apply to coordinated disclosure.
2. Scope of This Policy
This policy applies to:
- SECUSYSTS public websites and domains
- Client dashboards and portals operated by SECUSYSTS
- APIs, platforms, and services owned or managed by SECUSYSTS
This policy does not apply to:
- Third-party platforms not operated by SECUSYSTS
- Client-owned systems unless explicitly authorized in writing
Testing outside this scope is not permitted.
3. How to Report a Security Vulnerability
If you believe you have identified a security vulnerability affecting SECUSYSTS systems, please report it promptly using the method below.
Reporting Channel
Send details to: [email protected]
(If unavailable, reports may be sent to [email protected].)
Please include:
- A clear description of the vulnerability
- Affected system or URL
- Steps to reproduce (proof-of-concept if applicable)
- Potential impact assessment
- Your contact information
Do not include sensitive personal data in your report.
4. Responsible Disclosure Requirements
To qualify for responsible disclosure protections, you must:
- Act in good faith
- Avoid exploiting the vulnerability beyond what is necessary to demonstrate risk
- Avoid accessing, modifying, or deleting data
- Avoid service disruption (e.g., DoS/DDoS)
- Allow reasonable time for remediation before public disclosure
- Refrain from publicly disclosing details without written consent
Failure to follow these rules may result in loss of protections and potential legal action.
5. Safe Harbor (Good-Faith Research)
SECUSYSTS supports responsible security research conducted in good faith.
If you:
- Follow this policy
- Do not violate applicable laws
- Do not intentionally harm systems, data, or users
SECUSYSTS will not pursue legal action against you for the act of reporting the vulnerability.
This safe harbor does not apply to:
- Unauthorized penetration testing
- Social engineering attacks
- Physical security testing
- Denial-of-service attacks
- Extortion, ransom demands, or data exfiltration
6. Prohibited Activities (Critical)
The following activities are strictly prohibited unless explicitly authorized in writing by SECUSYSTS:
- Penetration testing, red teaming, or scanning
- Automated vulnerability scanning
- Exploitation of vulnerabilities
- Brute force or credential attacks
- Accessing customer or regulated data
Unauthorized activity may be treated as a security incident and handled accordingly.
7. Coordinated Disclosure Process
Upon receiving a valid report, SECUSYSTS will:
- Acknowledge receipt within a reasonable timeframe
- Assess and validate the vulnerability
- Prioritize remediation based on risk
- Communicate progress where appropriate
Disclosure timelines are coordinated and may vary depending on severity, complexity, and regulatory obligations.
8. No Bug Bounty Program
SECUSYSTS does not currently operate a public bug bounty program.
Submission of a vulnerability report:
- Does not guarantee compensation
- Does not create a contractual relationship
- Does not grant ownership or rights to SECUSYSTS systems
We reserve the right to acknowledge contributors at our discretion.
9. U.S. Federal & Regulated Systems Notice
For U.S. federal agencies, contractors, and regulated environments:
- Systems may be subject to mandatory reporting obligations
- Evidence preservation and audit requirements may apply
- Disclosure timelines may be constrained by law or contract
Unauthorized testing of regulated systems may trigger mandatory escalation.
10. Relationship to Other Policies
This Security Disclosure policy should be read together with:
In the event of conflict, contractual agreements govern.
11. Changes to This Policy
SECUSYSTS may update this Security Disclosure policy from time to time. Updates will be posted with a revised effective date.
12. Contact Information
For vulnerability reporting or security concerns:
Email: [email protected]
Email: [email protected]
Website: https://www.secusysts.com














