Security and Vulnerability Disclosure
Advanced Security Technologies (AST) welcomes reports of suspected security vulnerabilities in our products, services, and public infrastructure. This page describes how to report an issue to us and what you can expect in return.
How to report a vulnerability
Email with the subject line Security Vulnerability Report. A machine-readable version of this contact information is published at /.well-known/security.txt.
Please report privately and give us a reasonable opportunity to remediate before any public disclosure.
What to include
- The affected product, service, host, or URL
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept required
- Any relevant logs, requests, or screenshots
- How you would like to be credited, if at all
Scope
Public AST web properties and the AST product portfolio, including BaitHive Decoy, CATIS, NanoFirewall, ASPEN, and ShenDNS, are in scope.
The following are out of scope: denial-of-service and volumetric testing, social engineering or phishing of AST staff or customers, physical attacks, automated scanner output submitted without demonstrated impact, and findings that require a compromised device or privileged local access.
Rules of engagement
- Do not access, modify, or exfiltrate data that does not belong to you
- Do not degrade or interrupt AST or customer services
- Do not test systems belonging to AST customers without their own written authorisation
- Stop testing and report immediately if you encounter customer data or credentials
What you can expect from us
- Acknowledgement of your report within 3 business days
- An initial assessment and triage decision within 10 business days
- Regular updates while we work on a remediation
- Credit for your finding on request, once the issue is resolved
Safe harbour
AST will not pursue or support legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy. If a third party initiates action against you for activity conducted in compliance with this policy, we will make it known that your actions were authorised.
We do not currently operate a paid bug bounty programme.