security

Responsible disclosure

Of course, we at tradeinterop regard the security of our systems as very important. Despite our utmost care in securing our systems, it is possible that there is a weak spot.

If you have found a weakness in one of our systems, please let us know so that we can take action as quickly as possible. We would like to work with you to be able to protect our customers and our systems even better.

We ask you:

  • Email a security report to support@tradeinterop.com.

  • Do not exploit the problem by, for example, downloading more data than necessary to prove the leak or by accessing, deleting or modifying data of third parties.

  • Do not share the problem with others until it is solved.

  • Erase all data obtained through the leak.

  • Do not use physical security attacks, social engineering, distributed denial of service, spam or third-party applications.

  • Provide sufficient information to reproduce the problem so that we can solve it as soon as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability is sufficient, but more may be required for more complex vulnerabilities.

What we promise:

  • We will respond to your report within 3 days with our assessment of the report and an expected date for resolution.

  • If you have complied with the above conditions, we will not take any legal action against you regarding the report.

  • We will treat your report as confidential and will not share your personal data with third parties without your consent unless this is necessary to comply with a legal obligation. Reporting under a pseudonym is possible.

  • We will keep you informed of the progress in solving the problem.

  • In reporting the reported problem, we will, if you wish, mention your name as the discoverer.

  • We strive to solve all problems as quickly as possible and we are happy to be involved in any publication about the problem after it is solved.

Thank you for your help.

This text is based on the text by Floor Terra and is published under the Creative Commons Attribution 3.0 Unported license.