Security

Vulnerability disclosure program

Introduction

We value the contributions of the security research community and recognize the importance of a coordinated approach to vulnerability disclosure. If you have discovered a security vulnerability, we encourage you to let us know immediately. We welcome the opportunity to work with you to resolve the issue promptly.

Guidelines for reporting a vulnerability

  • Provide detailed reports with reproducible steps. Reports that cannot be reproduced may not be marked as triaged.
  • Submit one vulnerability per report unless vulnerabilities must be chained to demonstrate impact.
  • When duplicate reports occur, we triage the first reproducible report received.
  • Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
  • Social engineering, including phishing, vishing, and smishing, is prohibited.
  • Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services.
  • Only interact with accounts you own or accounts for which you have the account holder’s explicit permission.

What do we expect from you?

  • Submit your reports in English.
  • Always follow our responsible disclosure guidelines.
  • Ensure your report contains the following aspects:
  • Type of issue
  • Affected digital product, version, and software configuration
  • Step-by-step reproduction instructions
  • Proof of concept
  • Impact of the issue
  • Suggested mitigation or remediation, when appropriate

What can you expect from us?

  1. 1

    Acknowledgment: We will acknowledge receipt of your vulnerability report within five business days.

  2. 2

    Investigation: We will investigate thoroughly and work with you to understand the issue.

  3. 3

    Resolution: We will address the vulnerability in a timely manner and provide an estimated remediation timeline.

Safe Harbor

We will not pursue legal action against researchers who identify and report vulnerabilities in accordance with these vulnerability disclosure guidelines. Adhering to the rules of engagement outlined on this page is crucial. Your research activities must avoid violating user privacy, disrupting services, or accessing data beyond what is necessary to demonstrate the vulnerability. We also commit to not sharing your personal information without your consent, unless required by law.

Thank you for helping keep ADAMnetworks and our users safe.

Scope of reward program

We will accept submissions in any asset owned and operated by ADAMnetworks. To qualify for a reward, the scope of our program currently includes the following assets. We strive to reward any reports that result in a change on our end.

  • Public marketing website adamnet.works
  • ADAMnetworks Client Dashboard dashboard.adamnet.works
  • adam:ONE package
  • anmuscle
  • anckg
  • installer (platform specific)