alt

VULNERABILITY DISCLOSURE PROGRAM (VDP)

Last updated November 2024

We encourage responsible sharing of security vulnerabilities.

Safe Harbor

Researchers acting in good faith will not face:

  • Account termination
  • Legal action
  • Law enforcement referral

Reporting Channels

Send reports to:
security@journeycx.net

Include:

  • Description
  • Steps to reproduce
  • Screenshots (optional)
  • Impact assessment

Prohibited Testing

  • Social engineering JourneyCX staff
  • DOS attacks
  • Disruption of customer environments
  • Accessing data that is not yours

Response Time

  • Acknowledgement: 72 hours
  • Remediation target: 30 days (severity dependent)

Recognition

We may:

  • Credit researcher publicly (optional)
  • Issue thank-you acknowledgements