Security Incident Response Policy
Vuture uses best-practice Security Incident Response Processes to help quickly investigate, analyse, and resolve security incidents that warrant an investigation.
- Vuture and its partners are always on the alert for threats.
- When a threat is identified, engineers and security professionals are paged and mobilised.
- The engineering team investigates the issue and works with the security team to develop guidance for customers and partners.
- The account manager team provides guidance to customers, while the engineering team develops the solution.
- The security team then understand the root cause of the vulnerability, and put any preventative actions in to place immediately.
Report a Security Vulnerability
Vuture investigates all reports of security vulnerabilities affecting Vuture products and services immediately. If you are a security professional and believe you have found a Vuture security vulnerability, we would like to work with you to investigate it.
Please complete the below questionnaire and send this by e-mail to your Account Manager and include the Vuture security team at security@vutu.re.
To help us to better understand the nature and scope of the possible issue, please include as much of the below information as possible:
- Vuture Instance URL
- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue on a fresh install
- Proof-of-concept or exploit code
- Impact of the issue, including how an attacker could exploit the issue
Vuture follows very strict security requirements and, to protect the ecosystem, we request that those reporting to us do the same. You should receive a response within 24 hours. If for some reason you do not, please follow up with us to ensure we received your original message.
Vulnerability Terms and Conditions
By submitting this questionnaire, you agree that the information you have provided is true and accurate and that you agree to the following terms and conditions:
- You conducted your scans which identified the vulnerability using the approved Vuture vulnerability scan process.
- You are reporting the vulnerability to Vuture within 24 hours of identification by following the instructions in this document and will not disclose this information publicly or to any third party.
Vulnerability Resolution Times
Vuture will endeavour to meet the following best practice resolution times for identified and applicable vulnerabilities from the day of reporting (unless otherwise agreed):
| Vuture Classification |
Resolution time-frame
|
| Critical | 1 day |
| High | 3 days |
| Medium | 7 days (1 week) |
| Low | 30 days (1 month) |
| Informational | 180 days (6 months) |
Privacy
The information you share with us in this form will be kept confidential and used only to assist us with respect to your identified vulnerability and improving the security of the Vuture platform. Please see our privacy statement for more details: http://vutu.re/terms-and-conditions/privacy.aspx
Please download the questionnaire here.