Tool-O
Vulnerability Disclosure Policy
This Vulnerability Disclosure Policy explains how security researchers, Users and members of the public may responsibly report suspected security vulnerabilities affecting the Tool-O Platform.
1. INTRODUCTION
1.1 Purpose
This Vulnerability Disclosure Policy explains how security researchers, Users and members of the public may responsibly report suspected security vulnerabilities affecting the Tool-O Platform.
The purpose of this Policy is to encourage the responsible disclosure of security vulnerabilities so that Tool-O can investigate, assess and address potential security risks in a timely and responsible manner.
1.2 Objectives
This Policy seeks to:
- encourage responsible vulnerability reporting;
- improve Platform security;
- support coordinated vulnerability disclosure;
- protect Users and Platform information;
- promote responsible security research;
- minimise security risks;
- support continuous security improvement.
1.3 Scope
This Policy applies to suspected vulnerabilities affecting:
- the Tool-O website;
- mobile applications;
- User Accounts;
- authentication systems;
- APIs;
- Platform infrastructure;
- information systems;
- cloud services operated by or on behalf of Tool-O;
- other Platform services.
1.4 Guiding Principles
Tool-O administers vulnerability disclosure in accordance with the following principles:
- responsible disclosure;
- cooperation;
- confidentiality;
- accountability;
- proportionality;
- continuous improvement.
1.5 Relationship with Other Policies
This Policy should be read together with the:
- Security Policy;
- Incident Response Policy;
- Data Breach Response Policy;
- Privacy Policy;
- Platform Availability Policy;
- Acceptable Use Policy;
- Terms of Use;
- all other Platform policies.
1.6 Updates
Tool-O may amend this Vulnerability Disclosure Policy from time to time.
The latest version published on the Platform replaces all previous versions.
2. RESPONSIBLE VULNERABILITY DISCLOSURE
2.1 Reporting Vulnerabilities
Tool-O encourages responsible reporting of suspected security vulnerabilities affecting the Platform.
Reports should be submitted as soon as reasonably practicable after a potential vulnerability is identified.
2.2 Information to Include
Where reasonably possible, vulnerability reports should include:
- a description of the suspected vulnerability;
- affected systems or functionality;
- steps to reproduce the issue;
- proof of concept where appropriate;
- potential security impact;
- supporting technical information;
- contact details for follow-up communication.
2.3 Good Faith Research
Tool-O supports good faith security research conducted for the purpose of improving Platform security.
Researchers are expected to act responsibly and avoid activities that unnecessarily expose Users, systems or information to risk.
2.4 Prohibited Activities
Without Tool-O's prior written authorisation, researchers and other persons must not:
- intentionally access information belonging to other Users;
- modify Platform data;
- delete information;
- disrupt Platform operations;
- conduct denial-of-service attacks;
- deploy malicious software;
- engage in social engineering against Users or personnel;
- access systems beyond those reasonably necessary to demonstrate a
vulnerability;
- exploit vulnerabilities for personal benefit or unlawful purposes.
2.5 Confidentiality
Researchers are encouraged to keep details of suspected vulnerabilities confidential until Tool-O has had a reasonable opportunity to investigate and, where appropriate, remediate the issue.
2.6 Investigation
Upon receiving a vulnerability report, Tool-O may:
- acknowledge receipt;
- assess the reported issue;
- investigate the potential vulnerability;
- request additional information;
- determine appropriate remediation;
- monitor for related security issues.
2.7 Remediation
Where Tool-O confirms a vulnerability, it may take reasonable steps to:
- implement security fixes;
- strengthen security controls;
- update infrastructure;
- improve monitoring;
- revise operational procedures;
- reduce the likelihood of similar vulnerabilities.
2.8 Communication
Where reasonably appropriate, Tool-O may communicate with the reporting individual regarding:
- acknowledgement of the report;
- requests for additional information;
- investigation progress;
- confirmation of remediation where appropriate.
Tool-O does not guarantee that detailed investigation findings or remediation timelines will be disclosed.
2.9 No Guarantee of Reward
Unless Tool-O expressly operates a published vulnerability reward or bug bounty programme, submission of a vulnerability report does not entitle any person to:
- financial compensation;
- rewards;
- public recognition;
- contractual rights;
- reimbursement of expenses.
2.10 Responsible Security Collaboration
Tool-O values responsible collaboration with the security community and encourages good faith reporting that helps improve the security, resilience and integrity of the Platform while protecting Users and their information.
3. VULNERABILITY MANAGEMENT
3.1 Assessment
Tool-O may assess reported vulnerabilities by considering:
- the nature of the vulnerability;
- affected systems;
- potential impact;
- exploitability;
- potential harm to Users;
- operational risk;
- other relevant technical factors.
3.2 Prioritisation
Tool-O may prioritise remediation activities based upon factors including:
- severity;
- likelihood of exploitation;
- impact on Users;
- impact on Platform operations;
- availability of temporary mitigations;
- legal or regulatory obligations.
3.3 Temporary Protective Measures
Where reasonably necessary, Tool-O may implement temporary protective measures including:
- restricting affected functionality;
- disabling vulnerable features;
- applying temporary security controls;
- increasing monitoring;
- restricting access;
- implementing interim operational procedures.
3.4 Security Monitoring
Tool-O may monitor Platform systems to:
- detect attempted exploitation;
- identify related vulnerabilities;
- assess remediation effectiveness;
- strengthen Platform security;
- support incident response;
- improve future vulnerability management.
3.5 Third-Party Vulnerabilities
Where vulnerabilities involve third-party software, infrastructure or service providers, Tool-O may:
- notify the relevant provider where appropriate;
- cooperate in coordinated remediation;
- implement temporary mitigations;
- monitor vendor updates;
- apply security patches when reasonably practicable.
3.6 User Responsibilities
Users should:
- maintain appropriate Account security;
- install Platform updates where applicable;
- use supported software versions;
- promptly report suspected security issues;
- avoid attempting to exploit suspected vulnerabilities;
- cooperate with reasonable security requests.
3.7 Record Keeping
Tool-O may maintain records relating to reported vulnerabilities including:
- vulnerability reports;
- investigation records;
- remediation activities;
- communications;
- security assessments;
- corrective actions.
Records may be retained in accordance with the Data Retention Policy and applicable laws.
3.8 Security Improvements
Following remediation of vulnerabilities, Tool-O may implement improvements including:
- enhanced security controls;
- revised development practices;
- infrastructure upgrades;
- additional monitoring;
- revised operational procedures;
- security awareness initiatives.
3.9 Coordinated Disclosure
Where reasonably appropriate and after remediation or mitigation has been completed, Tool-O may coordinate public disclosure of a vulnerability with the reporting individual or relevant third parties.
Tool-O retains discretion regarding:
- the timing of any disclosure;
- the content of any disclosure;
- whether public disclosure is appropriate.
3.10 Responsible Vulnerability Management
Tool-O seeks to identify, assess, remediate and monitor security vulnerabilities responsibly while protecting Users, maintaining Platform security and supporting the continued resilience of the Tool-O marketplace.
4. REVIEW, COMPLIANCE AND POLICY ADMINISTRATION
4.1 Governance
Tool-O is responsible for administering this Vulnerability Disclosure Policy and may maintain internal procedures governing the receipt, assessment, remediation and documentation of reported security vulnerabilities.
4.2 Compliance
Tool-O seeks to manage reported vulnerabilities in accordance with applicable laws, regulatory requirements and recognised cyber security practices where appropriate.
Nothing in this Policy authorises any person to access, test or interfere with Platform systems in a manner that is unlawful or inconsistent with the Terms of Use.
4.3 Policy Review
Tool-O may periodically review this Policy to reflect:
- legislative changes;
- cyber security developments;
- regulatory guidance;
- operational experience;
- emerging threat landscapes;
- industry best practices;
- lessons learned from previous vulnerability reports.
4.4 Continuous Improvement
Tool-O may periodically review its vulnerability management processes to improve:
- security governance;
- vulnerability detection;
- remediation procedures;
- communication processes;
- operational resilience;
- Platform security.
4.5 Responsible Disclosure Framework
Tool-O encourages responsible vulnerability disclosure and seeks to foster constructive engagement with security researchers who act lawfully, responsibly and in good faith.
Nothing in this Policy obliges Tool-O to:
- accept every reported issue as a vulnerability;
- implement a particular remediation;
- publish investigation outcomes;
- disclose internal security information;
- provide financial rewards or public recognition.
4.6 Relationship with Other Policies
This Vulnerability Disclosure Policy should be read together with the:
- Security Policy;
- Incident Response Policy;
- Data Breach Response Policy;
- Privacy Policy;
- Platform Availability Policy;
- Acceptable Use Policy;
- Terms of Use;
- all other Platform policies.
Where there is any inconsistency, the Terms of Use prevail to the extent permitted by applicable law.
4.7 Contact
Suspected security vulnerabilities may be reported to Tool-O using the security contact details published on the Platform.
Users should avoid publicly disclosing vulnerabilities before Tool-O has had a reasonable opportunity to investigate and, where appropriate, remediate the issue.
4.8 Policy Updates
Tool-O may amend this Vulnerability Disclosure Policy from time to time.
The latest version published on the Platform replaces all previous versions.
4.9 Commitment
Tool-O is committed to maintaining a secure Platform through responsible vulnerability management, cooperation with good faith security researchers and the ongoing improvement of its security practices.
4.10 Final Statement
Responsible vulnerability disclosure strengthens the security and resilience of the Tool-O marketplace.
By encouraging timely reporting, investigating vulnerabilities responsibly and continually improving security controls, Tool-O seeks to protect its Users, safeguard Platform information and maintain trust in the Platform.
END OF VULNERABILITY DISCLOSURE POLICY
