🛡️ Overview of Our Security Program
Search Atlas takes the security of our platform and customer data seriously. We welcome reports from security researchers, customers, and the broader community who discover potential vulnerabilities in our systems. This article outlines our current policy for responsible disclosure and answers common questions about our security program.
🐛 Do We Have a Bug Bounty Program?
At this time, Search Atlas does not operate a formal, public bug bounty program with monetary rewards. We do not currently partner with third-party bug bounty platforms such as HackerOne or Bugcrowd. However, we do have a responsible disclosure policy that allows security researchers and users to report vulnerabilities directly to our team for review and remediation.
📋 What Is Responsible Disclosure?
Responsible disclosure is a process where a researcher or user who discovers a security vulnerability privately reports it to the affected organization before making it public. This gives the organization time to investigate and fix the issue, protecting users from potential exploitation during the remediation window.
We ask that anyone who discovers a potential security issue in Search Atlas:
- Report the issue privately and promptly rather than disclosing it publicly.
- Provide enough detail for our team to reproduce and understand the vulnerability.
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Refrain from performing denial-of-service attacks, social engineering, or phishing against our team or users.
- Allow our team reasonable time to investigate and address the issue before any public disclosure.
📬 How to Report a Security Vulnerability
To report a security vulnerability, please contact our support team directly through the Search Atlas platform. Include the following details in your report:
- Description: A clear summary of the vulnerability and the potential impact.
- Steps to reproduce: A step-by-step walkthrough that allows our team to replicate the issue.
- Environment details: The browser, device, or account type involved, if relevant.
- Supporting evidence: Screenshots, screen recordings, or logs that illustrate the issue.
Our team will review your report and follow up with you as the investigation progresses.
If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.