Legal · Armage LLC
Vulnerability Disclosure Policy
We welcome reports from security researchers. If you believe you have found a vulnerability in an Armage system, please tell us so we can fix it.
Introduction
This policy explains what you may test, how to report what you find and what you can expect from us. It is also published in machine-readable form at /.well-known/security.txt.
We do not currently offer payment for reports.
Safe harbour
If you make a good-faith effort to follow this policy:
- we consider your research authorised, and we will not take legal action against you for it;
- if someone else brings legal action about research that followed this policy, we will make it known that your work was authorised.
If you are unsure whether something is allowed, ask us at security@arm-age.com before you test.
Scope
In scope
arm-age.comand its subdomains operated by Armage.
Out of scope
- Services run by third-party providers we use. Report those directly to the provider.
- Denial of service, load or volume testing.
- Social engineering, phishing or physical attacks against Armage staff, offices or clients.
- Findings without a demonstrated security impact, such as missing headers on pages with no sensitive actions, software version disclosure, or reports from automated scanners alone.
Rules of engagement
- Access only the minimum data needed to show the vulnerability, and stop once you have.
- Do not change or delete data, and do not keep or share personal data you come across. If you find some, tell us in your report.
- Do not disrupt our services or degrade them for other users.
- Do not submit our contact or careers forms in bulk or with automated tools. Every submission emails a real person.
- Do not disclose details publicly until we have agreed a disclosure date together. Our target is to coordinate disclosure within 90 days of your report. Some issues take longer to fix safely; if so, we will explain why and agree a new date with you.
How to report
Email security@arm-age.com. Please include:
- the affected address or component;
- a description of the vulnerability and its impact;
- step-by-step instructions or a proof of concept to reproduce it;
- how you would like to be credited, if at all.
Reports in English are preferred. Do not include personal data belonging to others.
What to expect from us
- We aim to acknowledge your report within five business days.
- We will confirm whether we can reproduce the issue and keep you informed while we fix it.
- We will tell you when it is resolved.
- With your permission, we will publicly credit you once the issue is fixed.