Scope
This policy currently covers the public ERMAIGE website and other internet-accessible systems that ERMAIGE expressly identifies as in scope. Customer environments, third-party services, employee accounts, social engineering and systems not controlled by ERMAIGE are out of scope.
How to report
Email info@ermaige.com with “Security vulnerability” in the subject line. Include the affected asset, vulnerability type, steps to reproduce, potential impact and any supporting evidence. Do not include personal, confidential or unnecessarily sensitive data.
Research expectations
- Act in good faith and comply with applicable law.
- Avoid privacy violations, service disruption, degradation, denial of service and data destruction.
- Use the minimum testing needed to establish the issue and stop if you encounter sensitive information.
- Do not access, modify, download, retain or disclose data that does not belong to you.
- Do not use social engineering, phishing, physical attacks, credential stuffing or automated testing that creates material load.
- Give ERMAIGE a reasonable opportunity to investigate and address the issue before public disclosure.
Our response
ERMAIGE will acknowledge credible reports when practical, assess severity, coordinate remediation and keep the reporter informed at a level appropriate to the issue. Response and remediation times vary with complexity and risk. This is not a bug-bounty program and ERMAIGE does not promise payment or public recognition.
Authorization and limitations
Research conducted consistently with this policy is considered authorized for the limited purpose of identifying and reporting a vulnerability in an in-scope ERMAIGE asset. This authorization does not extend to third-party systems, activity prohibited by law, or activity outside this policy. ERMAIGE cannot authorize testing on behalf of another organization.