Vulnerability Disclosure Policy (VDP)
BaseCloud (Secure Managed Enterprise Cloud Platform) welcomes reports from independent security researchers. If you find a potential vulnerability in our systems or on basecloud.one, please report it under this policy.
Contact
- Security / VDP: [email protected]
- Abuse: [email protected]
- RFC 9116 file: /.well-known/security.txt
In scope
- Public sites and APIs under
basecloud.oneandwww.basecloud.one - Lead forms and endpoints (e.g.
/api/lead.php) — no mass spam - Externally visible HTTP/TLS/WAF issues that create real risk
Out of scope
- DoS / DDoS, flooding, or resource exhaustion
- Social engineering of staff, customers, or partners
- Physical intrusion, phishing, or malware delivery
- Scanning BaseCloud customer infrastructure or third-party sites
- High-volume automated scanning without rate limits and justification
- Cosmetic UI issues with no security impact
Safe research rules
- Do not modify or delete production data
- Do not exfiltrate personal data or secrets — a proof of concept is enough
- Do not leave persistent access (backdoors, unauthorized test accounts)
- Stop immediately if customer systems or regulated data are involved
How to report
Email [email protected] with:
- description and impact,
- reproduction steps or PoC,
- URL / component,
- approximate test time and source IP (optional),
- your reply contact.
Response SLA
- Acknowledgement: usually within 72 hours (business days)
- Initial assessment: usually within 14 days
- Coordinated disclosure: please withhold public release until a fix is agreed
Safe harbor
Good-faith research within this policy, without harming customer data, is authorized for responsible disclosure purposes. We will not pursue legal action against researchers who follow these rules. This is not a paid bug bounty — financial rewards are not guaranteed.
Acknowledgments
With your consent we may list your name or handle on this page after resolution. The list is currently empty.