Responsible Disclosure

Report a Vulnerability

We work with the security community to keep Vistaan and our customers safe. If you have found a vulnerability, please report it to us privately so we can investigate and fix the issue before public disclosure.

Policy

Scope

  • Production web properties under vistaan.com and its subdomains
  • Authenticated and unauthenticated access paths to customer-facing services
  • Configuration and hardening of infrastructure under Vistaan control

Out of scope

  • Denial-of-service attacks and rate-limit exhaustion
  • Social engineering of Vistaan staff or contractors
  • Vulnerabilities in third-party platforms we do not own
  • Self-XSS or issues requiring unlikely user interaction

Our commitments

  • Acknowledge your report within 2 business days
  • Provide a triage update within 5 business days
  • Share a remediation timeline once a fix is scoped
  • Credit researchers who follow the policy and request acknowledgement

Safe harbor

  • We will not pursue legal action for good-faith research that follows this policy
  • Research conducted under this policy is authorized and considered authorized access
  • You are not required to retain exfiltrated data — please delete it after confirmation

Secure contact channels

Email

security@vistaan.com

PGP-encrypted preferred. We acknowledge within 2 business days.

PGP fingerprint

3F4A 8C9B 21D6 7E05 9A11 6B22 4D88 7E33 0C55 91AB

Use this key when sending sensitive vulnerability details.

Signal

@vistaan-sec

Request a secure channel via Signal for high-severity reports.

Vulnerability template

Download .md

A short markdown template to help you structure your report.

Send a private report

Prefer to use the form? Submissions from this page go to our security team.

Questions about our security practices?