Responsible Disclosure Policy

TABLE OF CONTENTS

1. The Basics

  1. This Responsible Disclosure Policy ("Policy") outlines how security researchers and the public can report security vulnerabilities to AskField.
  2. AskField is committed to maintaining the security of our services and appreciates the responsible disclosure of security vulnerabilities.

2. Scope

This Policy applies to security vulnerabilities in:

  • AskField's web applications and services
  • AskField's mobile applications
  • AskField's APIs
  • AskField's infrastructure and systems

3. Reporting Vulnerabilities

To report a security vulnerability, please email security@askfield.com with the following information:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Suggested remediation, if any

4. Process

  1. Upon receiving a vulnerability report, AskField will acknowledge receipt within 48 hours.
  2. AskField will investigate and validate the reported vulnerability.
  3. AskField will work to remediate the vulnerability in a timely manner.
  4. AskField will notify the reporter when the vulnerability has been addressed.

5. Recognition

With the reporter's permission, AskField may recognize responsible disclosure in our security acknowledgments. We appreciate the security research community's efforts to help keep our services secure.