Acknowledge within 2 business days; critical fixes within 7 days — see § 2.
What's In Scope
Web app, API, bot client, and the channel between them — see § 3.
Safe Harbour
Good-faith research will not be prosecuted under our Terms or applicable law — see § 4.
We take the security of our platform seriously. If you believe you have found a vulnerability in Automize, this page tells you how to report it, what we commit to, and what is in scope.
Adhering to industry standards is important to us. Our programme is covered by Coordinated Vulnerability Disclosure (see § 5), Safe Harbor (see § 4), Open Scope (see § 3), Core Ineligible Findings (see the “findings we do not consider vulnerabilities” list in § 3), and HackerOne’s Detailed Platform Standards. Submissions go through our HackerOne managed VDP.
How a report moves from your inbox to a coordinated public fix.
1. How to Report a Vulnerability
Submit a Vulnerability Report
The fastest way to reach our security team. Submissions land in our HackerOne managed VDP queue and are acknowledged within 2 business days. Encryption, attachments, and follow-up are all handled in-platform.
If the form does not load (script blocker, restricted network) the alternative channels below remain open.
A clear description of the issue and the affected component (URL, endpoint, page, bot version).
Steps to reproduce, including any payload, request body, or screenshots.
The impact you believe the issue could have if exploited.
Your name or handle if you would like to be acknowledged (optional).
Please do not open a public GitHub issue, post on social media, or disclose to third parties before we have had a reasonable chance to investigate and remediate.
2. Our Commitments to You
When you report a vulnerability in good faith, we will:
Acknowledge your report within 2 business days.
Triage and provide an initial severity assessment within 5 business days.
Remediate on the timeline below, depending on severity.
Keep you informed of progress and notify you when a fix has shipped.
Credit you in our acknowledgments section (with your permission).
Not pursue legal action against researchers acting in good faith within this policy.
Our remediation targets:
Critical (e.g. authentication bypass, RCE, mass data exposure): patch within 7 days.
High (e.g. privilege escalation, sensitive data leak): patch within 30 days.
Medium (e.g. CSRF, stored XSS in low-traffic surface): patch within 60 days.
Low (e.g. information disclosure with limited impact): patch within 90 days or scheduled into a future release.
3. Scope
In scope:
The Automize web application served from automize.co.za and app.automize.co.za.
The Automize REST API at /api/v1/*.
The Automize Bot client (Windows desktop application).
The communication channel between bot and web (heartbeat, command, telemetry).
Authentication, authorisation, session management, and password reset flows.
Data isolation between tenants.
Out of scope:
Third-party services we depend on (AWS, SendGrid, WorkOS, PayFast, Anthropic, OpenAI, Sentry) — report directly to those providers.
Customer-authored bot processes or workflows (these are owned by the customer; report to the customer).
Social engineering of our staff, customers, or contractors.
Physical attacks against our offices, staff, or AWS data centres.
Denial of Service (DoS / DDoS) testing — do not run load or stress tests against our infrastructure.
Spam, brute-force, or credential-stuffing attempts (we rate-limit; please do not test these).
Issues that require a malicious browser extension, jailbroken device, or unrealistic threat model.
Content injection that requires an attacker to already control the victim’s browser or device.
Vulnerabilities in third-party libraries that we have already patched or that have no proof-of-concept against our deployment.
Reports generated solely by automated scanners without manual validation.
Common findings we do not consider vulnerabilities: missing security headers without a demonstrated attack vector; clickjacking on pages without sensitive actions; verbose error messages on non-production endpoints; rate-limit bypasses with no underlying impact; CSV injection in exported files; reports of HTTP options like TRACE without exploitation; SPF / DKIM / DMARC misconfiguration on non-mail-sending domains.
4. Safe Harbour
If you act in good faith and follow this policy:
We will not pursue civil or criminal action against you under the Computer Fraud and Abuse Act, similar laws in other jurisdictions, or our Terms of Service.
We will not contact your employer, your university, or law enforcement.
We consider your activity authorised research under this policy.
To remain within safe harbour:
Only test against your own account, or accounts you have explicit written permission to test.
Do not access, modify, delete, or exfiltrate other users’ data. If you accidentally encounter such data, stop immediately and tell us.
Do not run automated scanners against production for more than a brief, low-volume confirmation.
Do not publicly disclose the vulnerability until we have remediated and agreed on a coordinated disclosure timeline (typically 90 days from acknowledgement, sooner if remediated and agreed).
Comply with all applicable laws and our Terms of Service in every other respect.
5. Coordinated Disclosure
We follow a coordinated disclosure model:
You report the vulnerability privately.
We acknowledge, triage, and remediate.
Once a fix has shipped, we agree on a public disclosure date with you (typically the day of the fix or shortly after).
Where appropriate, we publish a security advisory and credit you in our acknowledgments section.
If a vulnerability is being actively exploited in the wild, we may disclose sooner to protect customers.
6. Rewards
We do not currently operate a paid bug bounty programme. We do publicly credit researchers (with permission) in the acknowledgments section below, and may at our discretion offer a token of appreciation for high-impact findings (e.g. branded merchandise, conference tickets).
We are evaluating a formal bug bounty programme for a future iteration of this policy.
7. Encrypted Communication (PGP)
For sensitive findings, you may encrypt your report with our PGP key. The key fingerprint and download link will be added to this section once published; in the interim, please request the key by email to security@automize.co.za and we will respond out-of-band.
8. Acknowledgments
We thank the following researchers for their responsible disclosures (with permission, in chronological order):