Terms & Policies

Vulnerability Disclosure Policy

Last update: April 7, 2020

1. Introduction

NetHunt CRM is committed to ensuring data security by protecting information from unwarranted disclosure. This policy is introduced to give security researchers guidelines for conducting vulnerability discovery activity and to inform on how to report discovered vulnerabilities. This policy describes what systems and types of activities are covered under this policy, how to send vulnerability reports, and how long we ask to wait before publicly announcing discovered vulnerabilities.

2. Guidelines

We request that you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or obtain data, establish command line access and/or persistence, or use the exploit to “pivot” to other systems.
  • Once you’ve established that a vulnerability exists or encounter any sensitive data (including personal data, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and keep the data strictly confidential.
  • Do not submit a high volume of low-quality reports.

3. Authorization

Security research conducted in accordance with this policy is considered authorized. We will work with you to understand and resolve the issue quickly, and NetHunt CRM will not recommend or pursue legal action related to your research.

4. Scope

This policy applies to the following systems and services:

  • nethunt.com web site
  • NetHunt CRM for Web
  • NetHunt CRM mobile application for Android
  • NetHunt CRM mobile application for iOS
  • NetHunt CRM browser extension for Chrome
  • NetHunt CRM browser extension for Safari
  • NetHunt CRM integration components listed here: https://nethunt.com/integrations

Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in third party solutions NetHunt CRM integrates with fall outside of this policy’s scope and should be reported directly to the solution vendor according to their disclosure policy (if any). If you aren’t sure whether a system or endpoint is in scope or not, contact us at security@nethunt.com before starting your research.

5. Types of testing

The following test types are not authorized:

  • Network denial of service (DoS or DDoS) tests.
  • Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing.§

6. Reporting a vulnerability

Please email security@nethunt.com to report any security vulnerabilities. We will acknowledge receipt of your vulnerability report the next business day and communicate with you further about our progress. Reports may be submitted anonymously.

7. Desirable information

In order to process and react to a vulnerability report, we recommend to include the following information:

  • Vulnerability description
  • Place of discovery
  • Potential impact
  • Steps required to reproduce a vulnerability (include scripts and screenshots if possible)

If possible, please provide your report in English.

8. Our commitment

If you choose to provide your contact information we commit to coordinating with you as openly and as quickly as possible. We will acknowledge within 3 business days that your report has been received.

To the best of our abilities we will keep you informed about vulnerability confirmation and remediation. We are opened to a dialogue for a discussion of issues.



NetHunt Inc.
651 N Broad St, Suite 206
Middletown, DE 19709
USA

Request a personalized product demo with our product expert

First Name *
Last Name *
Email *
Phone number * (+93) Afghanistan (+358) Åland Islands (+355) Albania (+213) Algeria (+1) American Samoa (+376) Andorra (+244) Angola (+1) Anguilla (+672) Antarctica (+1) Antigua and Barbuda (+54) Argentina (+374) Armenia (+297) Aruba (+61) Australia (+43) Austria (+994) Azerbaijan (+1) Bahamas (+973) Bahrain (+880) Bangladesh (+1) Barbados (+375) Belarus (+32) Belgium (+501) Belize (+229) Benin (+1) Bermuda (+975) Bhutan (+591) Bolivia, Plurinational State of (+599) Bonaire, Sint Eustatius and Saba (+387) Bosnia and Herzegovina (+267) Botswana (+47) Bouvet Island (+55) Brazil (+246) British Indian Ocean Territory (+673) Brunei Darussalam (+359) Bulgaria (+226) Burkina Faso (+257) Burundi (+855) Cambodia (+237) Cameroon (+1) Canada (+238) Cape Verde (+1) Cayman Islands (+236) Central African Republic (+235) Chad (+56) Chile (+86) China (+61) Christmas Island (+61) Cocos (Keeling) Islands (+57) Colombia (+269) Comoros (+243) Congo (+242) Congo, the Democratic Republic of the (+682) Cook Islands (+506) Costa Rica (+225) Côte d'Ivoire (+385) Croatia (+53) Cuba (+599) Curaçao (+357) Cyprus (+420) Czech Republic (+45) Denmark (+253) Djibouti (+1) Dominica (+1) Dominican Republic (+593) Ecuador (+20) Egypt (+503) El Salvador (+240) Equatorial Guinea (+291) Eritrea (+372) Estonia (+251) Ethiopia (+500) Falkland Islands (Malvinas) (+298) Faroe Islands (+679) Fiji (+358) Finland (+33) France (+594) French Guiana (+689) French Polynesia (+262) French Southern Territories (+241) Gabon (+220) Gambia (+995) Georgia (+49) Germany (+233) Ghana (+350) Gibraltar (+30) Greece (+299) Greenland (+1) Grenada (+590) Guadeloupe (+1) Guam (+502) Guatemala (+44) Guernsey (+224) Guinea (+245) Guinea-Bissau (+592) Guyana (+509) Haiti (+672) Heard Island and McDonald Islands (+39) Holy See (Vatican City State) (+504) Honduras (+852) Hong Kong (+36) Hungary (+354) Iceland (+91) India (+62) Indonesia (+98) Iran, Islamic Republic of (+964) Iraq (+353) Ireland (+44) Isle of Man (+972) Israel (+39) Italy (+1) Jamaica (+81) Japan (+44) Jersey (+962) Jordan (+7) Kazakhstan (+254) Kenya (+686) Kiribati (+850) Korea, Democratic People's Republic of (+82) Korea, Republic of (+383) Kosovo (+965) Kuwait (+996) Kyrgyzstan (+856) Lao People's Democratic Republic (+371) Latvia (+961) Lebanon (+266) Lesotho (+231) Liberia (+218) Libya (+423) Liechtenstein (+370) Lithuania (+352) Luxembourg (+853) Macao (+389) North Macedonia (+261) Madagascar (+265) Malawi (+60) Malaysia (+960) Maldives (+223) Mali (+356) Malta (+692) Marshall Islands (+596) Martinique (+222) Mauritania (+230) Mauritius (+262) Mayotte (+52) Mexico (+691) Micronesia, Federated States of (+373) Moldova, Republic of (+377) Monaco (+976) Mongolia (+382) Montenegro (+1) Montserrat (+212) Morocco (+258) Mozambique (+95) Myanmar (+264) Namibia (+674) Nauru (+977) Nepal (+31) Netherlands (+687) New Caledonia (+64) New Zealand (+505) Nicaragua (+227) Niger (+234) Nigeria (+683) Niue (+672) Norfolk Island (+1) Northern Mariana Islands (+47) Norway (+968) Oman (+92) Pakistan (+680) Palau (+970) Palestinian Territory, Occupied (+507) Panama (+675) Papua New Guinea (+595) Paraguay (+51) Peru (+63) Philippines (+64) Pitcairn (+48) Poland (+351) Portugal (+1) Puerto Rico (+974) Qatar (+262) Réunion (+40) Romania (+250) Rwanda (+590) Saint Barthélemy (+290) Saint Helena, Ascension and Tristan da Cunha (+1) Saint Kitts and Nevis (+1) Saint Lucia (+590) Saint Martin (French part) (+508) Saint Pierre and Miquelon (+1) Saint Vincent and the Grenadines (+685) Samoa (+378) San Marino (+239) Sao Tome and Principe (+966) Saudi Arabia (+221) Senegal (+381) Serbia (+248) Seychelles (+232) Sierra Leone (+65) Singapore (+1) Sint Maarten (Dutch part) (+421) Slovakia (+386) Slovenia (+677) Solomon Islands (+252) Somalia (+27) South Africa (+500) South Georgia and the South Sandwich Islands (+211) South Sudan (+34) Spain (+94) Sri Lanka (+249) Sudan (+597) Suriname (+47) Svalbard and Jan Mayen (+268) Swaziland (+46) Sweden (+41) Switzerland (+963) Syrian Arab Republic (+886) Taiwan, Province of China (+992) Tajikistan (+255) Tanzania, United Republic of (+66) Thailand (+670) Timor-Leste (+228) Togo (+690) Tokelau (+676) Tonga (+1) Trinidad and Tobago (+216) Tunisia (+90) Turkey (+993) Turkmenistan (+1) Turks and Caicos Islands (+688) Tuvalu (+256) Uganda (+380) Ukraine (+971) United Arab Emirates (+44) United Kingdom (+1) United States of America (+598) Uruguay (+998) Uzbekistan (+678) Vanuatu (+58) Venezuela, Bolivarian Republic of (+84) Vietnam (+1) Virgin Islands, British (+1) Virgin Islands, U.S. (+681) Wallis and Futuna (+212) Western Sahara (+967) Yemen (+260) Zambia (+263) Zimbabwe
Company website *

Thank you!

We'll be in touch soon to schedule a time.
Looking forward to helping you explore NetHunt CRM!