Responsible Disclosure

Last updated Feb. 20, 2024
Affective since Feb. 20, 2024

I. Welcome

We encourage you to contact us to report potential vulnerabilities in our systems.
This policy, along with all parts of our system are protected under copyright law. Do not attempt to duplicate or recreate our systems for any other use than single-use vulnerability testing.

II. Authorization

This section reflects our commitment to not take legal action against anyone in the general public for security research activities that represent a good faith effort to follow the policy.

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and The TinkerTechLab will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

II. Guidelines

Once you’ve established that a vulnerability exists or encountered any sensitive data (including personally identifiable information, or account information), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Under this policy, “research” means activities in which you:

The following test methods are not authorized for your use:

III. Scope

The following URIs are in-scope, and should be reported to The TinkerTechLab should a vulnerability be found.

The following URIs are not in-scope, and vulnerabilities should be reported to their respective maintainers.

Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us at [email protected] before starting your research.

IV. Reporting a vulnerability

Information submitted under this policy will be used for defensive purposes only: to mitigate or remediate vulnerabilities. We will not share your name or any contact information without prior express permission.

We accept vulnerability reports via [email protected]. Reports may be submitted anonymously. Reports may not be submitted to any other location. We do not support PGP-encrypted emails.

By submitting a vulnerability, you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against TinkerHost related to your submission. While you may be rewarded for successfully identifying and reporting a vulnerability, do not expect to receive compensation for submitting a report.

In order to help us triage and prioritize submissions, we recommend that your reports:

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible. To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution. You are welcome to ask follow-up questions about the process.

V. Questions

Questions regarding this policy may be sent to [email protected]. We additionally invite you to contact us with suggestions for improving this policy.