Response SLA

Leadership reply within 24 hours

Delivery Regions

USA, Spain, India, Ecuador, and global remote

Engagement Control

NDA-first, written authorization required

Control Alignment

Mapped to SOC 2, ISO 27001, PCI DSS, HIPAA

Policy

Responsible disclosure policy.

We welcome responsible reports and coordinate remediation with clear communication and safety controls.

Version

Disclosure Policy v2.7

Owner

Security Response Team

Status

Public Policy, Actively Enforced

Last updated

February 19, 2026

Safe harbor expectations

Only non-destructive testing, no privacy violation, no service disruption, and no unauthorized data access.

Response timeline

Acknowledgement within 24 hours, triage in 3 business days, and remediation coordination thereafter.

Disclosure coordination

Please allow sufficient remediation time before public disclosure; we provide status updates throughout.

Out of scope activities

01

No social engineering

Do not target employees, partners, or clients through phishing/vishing.

02

No denial of service

Do not execute stress or disruption testing on production services.

03

No data exfiltration

Do not access, copy, or expose sensitive information.