Security Vulnerability Reporting Policy
Last updated: April 2026
Report a Vulnerability
Send all security disclosures to security@tebrim.com. We respond within 2 business days.
Tebrim takes the security of our platform, infrastructure, and customers' data seriously. We believe that working with security researchers and the broader security community strengthens the security posture of everyone who relies on Tebrim. If you have discovered a potential security vulnerability in any Tebrim-owned system, website, or service, we encourage you to disclose it to us responsibly. We are committed to working with researchers in good faith, investigating all reports promptly, and recognizing your contribution.
The following Tebrim-owned assets are in scope for responsible disclosure: • The Tebrim SaaS Platform (app.tebrim.com) — all authenticated and unauthenticated surfaces. • Tebrim public APIs and documented API endpoints. • Tebrim's main website (tebrim.com) and any subdomains serving dynamic content. • Tebrim-published open-source repositories (where applicable). • Authentication and identity management flows (login, SSO, MFA, session management).
The following are explicitly out of scope. Reports regarding these issues will not be eligible for acknowledgment and may constitute unauthorized activity: • Third-party services and infrastructure not owned or operated by Tebrim. • Denial of Service (DoS/DDoS) attacks against any Tebrim system. • Physical attacks against Tebrim offices, hardware, or personnel. • Social engineering, phishing, or vishing attacks targeting Tebrim employees or customers. • Vulnerabilities in end-user devices, browsers, or operating systems that are not specific to Tebrim software. • Automated scanning that impacts service availability or degrades performance for other users. • Known vulnerabilities with public CVEs that are already in our remediation pipeline. • Theoretical vulnerabilities without a demonstrated proof of concept. • Self-XSS or attacks requiring physical access to an authenticated user's device.
Please submit all vulnerability reports directly to our security team via email: security@tebrim.com To help us triage and respond efficiently, please include: • A clear description of the vulnerability type (e.g., SQLi, SSRF, IDOR, broken auth). • The affected URL, endpoint, or component. • Step-by-step reproduction instructions, including any payloads used. • The potential impact you observed or assessed. • Screenshots, video recordings, or proof-of-concept code (if available and safe to share). • The tools and techniques used (so we can understand scope and assess customer impact). You may encrypt sensitive reports using our PGP public key, available at tebrim.com/pgp-key.txt. Please do not use automated vulnerability scanners in a way that generates significant traffic or that tests production accounts belonging to other customers.
Upon receiving your report, Tebrim commits to: • Acknowledgment: Confirm receipt of your report within 2 business days. • Triage: Provide an initial assessment of severity and scope within 5 business days. • Investigation: Conduct a thorough internal investigation and keep you informed of progress at meaningful milestones. • Remediation: Work to remediate confirmed vulnerabilities in accordance with their severity: – Critical (CVSS 9.0–10.0): Targeted remediation within 7 days. – High (CVSS 7.0–8.9): Targeted remediation within 30 days. – Medium (CVSS 4.0–6.9): Targeted remediation within 90 days. – Low (CVSS < 4.0): Remediated in a future release cycle. • Notification: Notify you when the vulnerability has been resolved. • Coordination: Work with you on coordinated disclosure if you intend to publish your findings.
Tebrim will not pursue civil or criminal legal action against researchers who: • Discover and report vulnerabilities in good faith, following this policy. • Do not access, exfiltrate, modify, or destroy customer data beyond what is necessary to demonstrate the vulnerability. • Do not disrupt or degrade Tebrim services or third-party systems. • Do not publicly disclose vulnerability details before Tebrim has had a reasonable opportunity to remediate (we request a minimum coordinated disclosure window of 90 days from confirmed receipt). • Do not exploit vulnerabilities for personal gain or to harm Tebrim or its customers. We consider responsible security research conducted within these guidelines to be authorized activity. If you have any doubts about whether a specific action is in scope or authorized, please ask before proceeding: security@tebrim.com.
When investigating vulnerabilities, you must: • Only test against accounts and environments you own or have explicit written permission to test. • Avoid accessing, downloading, modifying, or deleting data that does not belong to you. • Immediately stop testing and report to us if you inadvertently access customer data. • Not perform denial of service testing, fuzzing at high volume, or any action that could impair system availability. • Not attempt to access Tebrim infrastructure beyond the surface area of the application itself (e.g., do not attempt to pivot to internal networks). • Comply with all applicable laws in your jurisdiction.
Tebrim believes in the principle of coordinated (or "responsible") disclosure — giving vendors a reasonable window to remediate vulnerabilities before public disclosure. We ask researchers to allow a minimum of 90 days from the date Tebrim confirms receipt and validity of a report before publishing any information about the vulnerability. If you plan to present findings at a security conference, publish a blog post, or submit a CVE, please let us know in advance so we can coordinate. We aim to support your ability to publish your work after remediation is complete.
Tebrim acknowledges the hard work of security researchers who contribute to our security. For valid, in-scope vulnerability reports, we offer: • Public acknowledgment in Tebrim's Security Hall of Fame (with your permission). • Written recognition letter upon request. • Coordinated CVE assignment assistance for qualifying vulnerabilities. At this time, Tebrim does not operate a formal bug bounty program with monetary rewards. We reserve the right to introduce such a program in the future. We are committed to fair treatment of all researchers who act in good faith within these guidelines.
This policy does not create a contract or any legal obligation between Tebrim and security researchers. Tebrim reserves the right to determine, at its sole discretion, whether a report qualifies as a good-faith disclosure under these guidelines. This policy does not authorize testing of third-party systems or customer environments. Unauthorized access to customer data is a violation of applicable law and these guidelines regardless of intent. Tebrim will interpret this policy in the spirit of encouraging responsible security research while protecting our customers, infrastructure, and operations.
Security Disclosures: security@tebrim.com General Inquiries: contact@tebrim.com PGP Key: tebrim.com/pgp-key.txt Mailing Address: Tebrim, Inc., Attn: Security Team, [Address], United States