Responsible Disclosure Policy
Security is a core priority at LORIQ Technologies. We value the role of independent security researchers and ask that you follow this Responsible Disclosure Policy if you discover a vulnerability in our systems.
1. How to Report
If you believe you have found a security vulnerability in our products or services, please report it to us via email at: info@loriqtechnologies.com
Please include:
- A detailed description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce the issue.
- Any proof-of-concept code or screenshots.
2. Testing Boundaries
Authorized testing is limited to:
- Web applications and APIs explicitly owned and operated by LORIQ.
- Interactions strictly utilizing accounts that you own or have explicit permission to test against.
3. Prohibited Actions
When conducting security research, you must not:
- Perform Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
- Access, modify, or destroy Customer Business Data belonging to others.
- Engage in social engineering, phishing, or physical attacks against LORIQ employees or facilities.
- Exploit vulnerabilities beyond what is necessary to prove their existence (e.g., establishing persistence or lateral movement).
4. Acknowledgment Process
LORIQ will make reasonable efforts to acknowledge legitimate security reports promptly. We evaluate reports based on severity and impact, and we request that you maintain confidentiality until we have had adequate time to implement a fix.
5. Safe Harbor
If you conduct your security research in good faith and in full compliance with this policy, we will consider your actions authorized. We will not pursue civil action or initiate a complaint to law enforcement for accidental, good faith violations of this policy.
Contact Information
For questions regarding this policy, please contact us at:
