On this page
01 Our commitment
Protecting our customers' data is a priority, and no system is perfect. We welcome reports of security issues and will work with you to understand and resolve them quickly. We commit to responding to good-faith reports, keeping you informed of our progress, and not pursuing legal action against researchers who follow this policy.
↑ Back to top02 Scope
This policy applies to security vulnerabilities discovered in:
- our website at outcome1.ai; and
- our application at platform.outcome1.ai.
If you are unsure whether something is in scope, contact us before testing and we will let you know.
↑ Back to top03 How to report
Please send your report to security@outcome1.ai. To help us assess and reproduce the issue quickly, please include:
- a description of the vulnerability and its potential impact;
- clear steps to reproduce it, including any proof-of-concept;
- the affected URL, system or component; and
- any tools, configurations or accounts you used.
Please report a vulnerability as soon as you can after discovering it, and give us a reasonable opportunity to address it before disclosing it to anyone else.
↑ Back to top04 What to expect from us
When you report a vulnerability in line with this policy, we will:
- acknowledge receipt of your report in good faith and as promptly as we reasonably can;
- provide an initial assessment and keep you informed as we investigate;
- work to remediate confirmed vulnerabilities on a best-effort basis, in a timeframe appropriate to their severity; and
- let you know when the issue has been resolved.
We do not commit to fixed response or resolution deadlines, but we treat security reports as a priority and will give yours prompt attention.
↑ Back to top05 Safe harbor
We consider security research and vulnerability disclosure carried out in accordance with this policy to be authorised conduct. If you act in good faith and within this policy, we will not pursue or support legal action against you in relation to your research, and we will treat your activity as authorised under applicable computer-misuse and similar laws to the extent we are able.
This protection applies only while you comply with this policy. It does not extend to actions that go beyond it, and it cannot waive the rights of third parties. If legal action is initiated by someone else against you for activity conducted in line with this policy, we will make clear that your conduct was authorised by us.
↑ Back to top06 Guidelines for researchers
To stay within this policy, please:
- act in good faith and avoid any privacy violations, disruption to others, or destruction of data;
- only interact with accounts you own or have explicit permission to test;
- access only the minimum amount of data needed to demonstrate the vulnerability, and never view, store, transfer or use anyone else's data;
- stop testing and notify us immediately if you encounter personal data or sensitive information; and
- keep the details of any vulnerability confidential until we have resolved it and agreed timing for disclosure with you.
07 Out of scope
The following are not authorised under this policy, and we ask that you do not attempt them:
- denial-of-service attacks, or any testing that degrades or disrupts the service;
- social engineering of our staff, customers or vendors, and physical attacks against our offices or people;
- spam, or automated testing that generates excessive traffic;
- accessing, modifying or deleting data that does not belong to you beyond what is strictly necessary to demonstrate an issue; and
- vulnerabilities in third-party services or integrations that we do not control, which should be reported to the relevant provider.
08 Recognition
We are grateful to the researchers who help keep our service and our customers safe. With your permission, we are happy to acknowledge your contribution once an issue has been resolved.
↑ Back to top09 Legal
This policy does not grant any rights beyond the authorisation described in Section 5, and nothing in it should be read as permission to act unlawfully. We may update this policy from time to time, and the version published here is the one that applies. If you have any questions about this policy, contact us at security@outcome1.ai.
