Skip to content
Request a meeting

Vulnerability Disclosure Policy

Metrikus Limited Vulnerability Disclosure Policy

Metrikus takes security issues extremely seriously. Using our site, you confirm that you accept these terms of use and that you agree to comply with them.

If you believe you have found a security vulnerability in our platform/or website, please submit your report to us.

1. Introduction
This Vulnerability Disclosure Policy (Policy) applies to any vulnerabilities you are considering reporting to us, (Metrikus).

Please review this Policy fully before you report a vulnerability, and we request that you comply fully with it before filing such submissions.

We value those who take the time and effort to report security vulnerabilities in accordance with this policy. Please we note, we may offer monetary rewards for vulnerability disclosures at our sole discretion.

2. Reporting
If you believe you have discovered a security vulnerability that affects our software or services, please submit your report to us at security@metrikus.io
 

We request all reports to include the following details for our review and assessment to assist us in ensuring that the report can be triaged quickly and accurately to reduce the likelihood of duplicate reports, and/ or malicious exploitation of such vulnerabilities:

  • the website, IP or page where the vulnerability can be observed
  • a brief description of the type of vulnerability
  • steps to reproduce; which should be a benign, non-destructive, proof of concept.
Notwithstanding the above, some vulnerabilities may be considered out of scope for bounty consideration, which will be at the sole discretion of Metrikus and such decision shall be final and binding, and Metrikus shall not be held liable for any further costs, bounty or reward in any matter whatsoever.

Vulnerabilities that will not be considered include but are not limited to; non-exploitable, theoretical issues that do not affect Confidentiality, Integrity or Availability or the system, such as:

  • Lucky13 Cloudflare TLS ciphers that are mitigated by modern browsers.
  • Certificate Authority Authorization records.
  • Re-dressing and Clickjacking attacks based on X-Frame-Options.
  • Browser issues such as Content-Security-Policy or Permissions-Policy.
  • Non-exploitable vulnerabilities detected by automatic scanners.
  • Denial of Service attacks.
Systems completely out of scope include, but not limited to:

  • Issues found on our marketing website at https://www.metrikus.io
  • Attacks against our vendors.
3. What to expect
Following receipt of your report, we will endeavour to respond within 14 working days and aim to triage your report within 1 month; and may aim to keep you up to date of our progress.

Our priority for remediation shall be assessed by looking at the impact, severity and exploit complexity.
 
Vulnerability reports might take some time to triage and/ or address. We will notify you when the reported vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately.

Public disclosures may be approved at Metrikus’ sole discretion, should you wish to request to disclose your report, requests for approval shall be submitted to security@metrikus.io for approval.

4. Guidance
You must NOT:
 
  • break any applicable law or regulations
  • access unnecessary, excessive or significant amounts of data
  • modify data in the Metrikus ’s systems or services
  • use high-intensity invasive or destructive scanning tools to find vulnerabilities
  • attempt or report any form of denial of service, for example, overwhelming a service with a high volume of requests
  • disrupt the Metrikus ’s services or systems
  • submit reports detailing non-exploitable vulnerabilities, or reports indicating that the services do not fully align with “best practice”
  • communicate any vulnerabilities or associated details other than by means described in this Policy
  • engineer, ‘phish’ or physically attack the Metrikus ’s staff or infrastructure
  • demand financial compensation in order to disclose any vulnerabilities
  • share, redistribute or fail to properly secure data retrieved from the systems or services.

You must:

  • comply with data protection rules
  • not violate the privacy of the Metrikus ’s users, staff, contractors, services or systems.
  • securely delete all data retrieved during your research as soon as it is no longer required or within 1 month of the vulnerability being resolved, whichever occurs first (or as otherwise required by data protection law).

5. Legalities
This
policy is intended to be compatible with common vulnerability disclosure good practice, and does not give you permission to act in any manner that is inconsistent with the law, or which might cause the Metrikus or partner organisations to be in breach of any legal obligations.

Published: May 2023
Version: 1
Policy Owner: Chief Product and Technology Officer, Product and Engineering Department
ISMS Classification - Public. Uncontrolled once printed 
 

×

Book a demo

Book a demo
STANDARD_PAGE