TotalCtrl holds business-critical data for the organizations that use it, so
we would much rather hear about a security problem from you than discover it
later. If you have found a vulnerability in our platform, we want your
report, and this page tells you how to send it and what we will do with it.
We welcome reports from anyone. You do not need an account, an invitation,
or a prior relationship with us, and you will never be charged for the time
you spend telling us about a flaw.
The URL, endpoint, or feature affected, and the type of issue.
Steps to reproduce it, in enough detail that we can follow them. A short
video or a request/response capture is often the fastest thing to send.
What an attacker could actually do with it, and any preconditions
(for example, whether it needs an authenticated account, or a particular
role).
Any account identifiers, timestamps, or IP addresses you used, so we can
find your activity in our logs and separate it from real attacks.
How you would like to be credited, if you would like to be.
Write in English if you can. Reports in other languages are still welcome and
we will translate them.
What we commit to
Acknowledgment within 3 business days of your report
reaching us — from a person, not an autoresponder.
An assessment within 10 business days: whether we have
reproduced the issue, how we rate its severity, and what we intend to do.
Progress updates at least every 14 days while the issue
is open, without you having to ask.
Notice when it is fixed, and an offer to have you verify
the fix.
Credit where you want it. We will name you in our
acknowledgments, or keep your report anonymous — your choice, and we will
ask before publishing anything.
We aim to remediate critical issues within 30 days of confirming them. Where
a fix will take longer, we will tell you why and give you a target date
rather than letting the thread go quiet.
Safe harbor
If you make a good-faith effort to comply with this policy during your
research, we will treat your work as authorized. Specifically:
We will not bring legal action against you, or refer you for
prosecution, in relation to your research.
We will not report your activity to law enforcement, and if a third
party brings action against you for research conducted under this policy,
we will make it known that your work was authorized.
We will treat your testing as authorized conduct under the Computer
Fraud and Abuse Act, the Digital Millennium Copyright Act's
anti-circumvention provisions, and comparable laws elsewhere, and we
waive any claim under our Terms of Service that would otherwise prohibit
it.
We will work with you to understand your report quickly, and will not
treat an honest mistake in your testing as bad faith.
This authorization covers your research only, and it cannot bind anyone but
us — it does not extend to systems operated by our subprocessors or by other
third parties. If you are unsure whether something is in scope, ask us
first at security@totalctrl.app
and we will answer.
Scope
In scope:
totalctrl.app and its subdomains, including
www.totalctrl.app and api.totalctrl.app.
The TotalCtrl web application and its public REST API.
The TotalCtrl mobile applications.
Customer-facing pages we serve on our own infrastructure, such as Help
Centers, Client Portals, and public boards — including where a customer
has pointed their own domain at them.
Out of scope:
Systems and services operated by third parties, including our
subprocessors. Report
those to the party that runs them.
Denial of service, volumetric testing, and anything else whose method is
to degrade the service for other people.
Social engineering, phishing, or physical attacks against our staff,
users, or offices.
Findings that are only the output of an automated scanner, with no
demonstrated impact.
Missing hardening headers, cookie flags, TLS configuration preferences,
and similar best-practice gaps, unless you can show a concrete exploit.
Software version disclosure, and vulnerabilities in third-party
dependencies for which no working exploit against TotalCtrl is shown.
Email deliverability configuration (SPF, DKIM, DMARC) on domains that
do not send our mail.
Self-inflicted issues that require a victim to paste code into their own
browser console, or to install a malicious extension.
Reports about our own security-policy choices without an accompanying
vulnerability. We will read them, but they are not disclosures.
Rules of engagement
To stay within this policy, please:
Use your own data. Create a free workspace and test
against that. Do not access, modify, or download data belonging to anyone
else.
Stop when you have proof. Once you can demonstrate a
vulnerability, stop — do not enumerate further records, escalate for its
own sake, or maintain access.
Tell us immediately if you encounter other people's data,
stop testing, and do not save, copy, or share it.
Do not degrade the service. Keep automated traffic to a
reasonable rate and never test in a way that affects other users'
availability.
Do not use a vulnerability beyond what is needed to confirm it
— no persistence, no pivoting, no backdoors, and remove any test artifacts
you leave behind.
Give us time to fix it. Please keep the issue
confidential until we have shipped a fix, and coordinate publication with
us. We will not ask you to stay quiet indefinitely: if we have not fixed
an issue within 90 days of confirming it, you are free to
publish, and we would appreciate a heads-up first.
Do not extort us. Withholding details pending payment,
or threatening publication to force one, is not good-faith research and
the safe harbor above does not cover it.
Rewards
This policy is about getting the report to us, and it carries no payment
requirement in either direction. We do run a separate
bug bounty program under
which qualifying reports may be rewarded — reporting here is how you enter
it, and you never have to ask about money to be taken seriously.
Questions about this policy, or about whether something is in scope, go to
security@totalctrl.app. If you
are a customer reporting suspected unauthorized use of your own account,
email us at the same address and say so in the subject line — we prioritize
those.