- Tel: +44 730 458210
- Fax: +44 730 458444
- Mail: support@Asset-Claims.com
Welcome to the Responsible Disclosure Policy of Asset Claims LTD. This page outlines the principles that guide how Asset Claims LTD handles security vulnerabilities and ethical disclosures to protect users and systems worldwide.
Encourage responsible reporting of vulnerabilities that may affect the security or privacy of Asset Claims LTD systems.
This policy covers websites, APIs, applications, and systems owned and operated by Asset Claims LTD.
Independent security researchers, ethical hackers, and cybersecurity experts acting in good faith.
Asset Claims LTD revises this policy annually to align with global security standards and industry regulations.
We will acknowledge vulnerability reports within 3 business days of receipt.
Asset Claims LTD commits to triaging and analyzing reported vulnerabilities promptly.
Critical vulnerabilities will be addressed with urgency, and all issues will be mitigated based on severity.
Subject to Asset Claims LTD discretion, researchers may be publicly acknowledged for significant contributions.
All vulnerability reports must be submitted to security@asset-claims.com.
Reports should include detailed reproduction steps, technical analysis, and potential impact assessment.
Asset Claims LTD ensures that personal researcher information remains confidential unless otherwise agreed.
Investigations are conducted within defined SLAs based on the severity of the reported issue.
Security is integrated into every phase of our system development and operational processes.
Asset Claims LTD conducts regular cybersecurity awareness training for all employees.
We implement threat modeling practices to anticipate and mitigate risks proactively.
We continuously monitor, detect, and address vulnerabilities across our environments.
Researchers must avoid harming users, accessing private data, or disrupting systems.
No copying, downloading, or exfiltration of company or customer data is permitted.
Do not use social engineering tactics such as phishing against employees or customers.
Testing must remain within the predefined scope outlined by Asset Claims LTD.
Immediate threats to data confidentiality, system availability, or integrity.
Issues posing substantial risk requiring swift resolution but not immediately critical.
Risks mitigated through standard controls or procedural adjustments.
Findings that do not pose significant risk but help strengthen overall security posture.
Public websites, customer-facing APIs, and proprietary mobile applications.
Third-party systems and platforms not owned or operated directly by Asset Claims LTD.
Certain elements of cloud-hosted infrastructure may be included with prior written consent.
Newly launched platforms will be assessed and added to the scope as applicable.
Accessing, modifying, or destroying any data is strictly prohibited.
Denial-of-Service (DoS/DDoS) attacks, network stress testing, or similar activities are forbidden.
No phishing emails, phone scams, or impersonation tactics allowed under any circumstances.
Physical security tests against facilities or personnel are out of scope.
Send all reports to our dedicated security mailbox: security@asset-claims.com.
Detailed description, proof of concept, and impact analysis must accompany all submissions.
Optionally encrypt reports with our published PGP key to maintain confidentiality.
For actively exploited vulnerabilities, urgent escalation paths are available upon request.
All reports are initially reviewed by our triage team to validate authenticity and severity.
Reports are categorized based on business impact and technical risk factors.
Our engineering teams work to deploy patches or configuration changes as required.
Post-remediation, independent verification is conducted to ensure the issue is fully resolved.
Asset Claims LTD will send confirmation of receipt for all reports within 3 business days.
Researchers will be provided with periodic updates regarding progress on validation and remediation.
In cases requiring clarification, researchers may be contacted for additional information or assistance.
Asset Claims LTD may request nondisclosure during active remediation efforts to protect client security.
Researchers who comply with all rules and contribute valid vulnerabilities may be included in our Hall of Fame.
Public recognition will only occur with the researcher’s explicit consent.
Recognition, if granted, typically occurs within 30 days post-remediation.
Asset Claims LTD does not provide financial bounties; acknowledgment is honorary.
Asset Claims LTD protects the privacy of all reporters unless legally required otherwise.
Reports and associated communications are stored securely within encrypted systems.
Only authorized personnel within Asset Claims LTD have access to vulnerability information.
Reports are retained for audit and compliance purposes for a minimum of 3 years.
Researchers acting in good faith within the boundaries of this policy will not face legal action.
Good faith is contingent on avoiding data destruction, privacy violations, and service disruption.
Reports affecting third-party services should be submitted directly to the provider unless involving Asset Claims LTD data.
Safe Harbor protections apply only when rules are respected throughout the research and reporting process.
Asset Claims LTD provides no warranty regarding the processing of vulnerability reports.
No compensation, liability, or damages are extended for researchers beyond acknowledgment.
Asset Claims LTD is not liable for incidental disruptions stemming from good-faith vulnerability testing.
All legal matters arising from this program are governed by English law.
Asset Claims LTD may revise or terminate this policy at any time without prior notice.
New assets, endpoints, or exclusions may be updated within scope documentation as necessary.
Major changes will be communicated via the Asset Claims LTD website or designated communication channels.
All policy versions will be archived for compliance and transparency purposes.
Receipt of report acknowledged within 3 business days.
Initial triage and risk assessment conducted within 7 business days of acknowledgment.
Critical issues patched within 30 days; non-critical based on risk priority.
Researchers will be consulted regarding public disclosure timing post-remediation.
Working with researchers enhances the overall resilience of Asset Claims LTD’s systems.
Early detection of vulnerabilities significantly reduces risk exposure.
Responsible disclosure supports compliance with data protection and cybersecurity regulations.
Transparent handling of vulnerabilities strengthens customer and partner trust.
Researchers must act ethically, avoiding harm or unauthorized exposure of data.
All communications with Asset Claims LTD should remain courteous and professional.
Exploiting vulnerabilities beyond proof of concept is strictly prohibited.
Testing activities must stay within the defined scope boundaries at all times.
We value ongoing partnerships with the security research community worldwide.
Asset Claims LTD is dedicated to improving our security infrastructure year after year.
We respect the work of ethical hackers and recognize their role in creating safer digital ecosystems.
Thank you for collaborating with Asset Claims LTD in strengthening global cybersecurity defenses.