Vulnerability Disclosure Policy

1. About this document

This document outlines the Vulnerability Disclosure Policy for Tupl, Inc., a Delaware corporation, hereinafter "Tupl". It details how to report potential security vulnerabilities in Tupl systems and services and includes guidelines for ethical hacking, the scope of in-scope and out-of-scope reports, and our commitment to legal protection and confidentiality for researchers. This policy ensures that vulnerabilities are reported and addressed responsibly.

If you believe you have found a security vulnerability on one of Tupl web sites or in Tupl apps, we thank you in advance for letting us know right away. We will investigate all legitimate reports and strive to address any security issues promptly.

This policy must be read and understood before any security research is conducted or any reports are submitted. Compliance with this policy is required to ensure that security vulnerabilities are reported and handled in a responsible manner, protecting both the researchers and Tupl.

2. Rewards

Tupl does not currently offer a reward program; thus, there will not be any compensation, reward or public recognition for submittal of potential vulnerabilities. By submitting a vulnerability, you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against Tupl related to your submission.

3. Authorization

If you make a good faith effort to comply with this policy during your security research, Tupl will consider your research to be authorized, will work with you to understand, and resolve the issue quickly, and Tupl will not recommend or pursue legal actions related to your research.

4. Guidelines for operating in good faith

Under this policy, "research" means activities in which you: Notify us as soon as possible after discovering a real or potential security issue; Avoid disruptive actions against Tupl systems; Keep the information related to the discovered vulnerability confidential; Avoid privacy violations or any destruction, modification or exfiltration of Tupl data; Use exploits only to the extent necessary to confirm a vulnerability's presence; Do not submit low-quality reports; Once you have established that a vulnerability exists or encounter any sensitive data, you must stop your test, notify us immediately, and not disclose this data to anyone else.

5. Out of Scope Reports and Ineligible Findings

The following vulnerabilities are out of scope:

6. Systems in Scope

This policy applies to:

Any service not listed is excluded from scope.

7. Contact Information

To disclose a potential vulnerability, please email: cybersecurity.support@tupl.com. We will not share your name or contact information without express permission.

8. Response Time

We commit to acknowledging receipt of your vulnerability report within 5 business days and will keep you informed about the progress.

9. Public Disclosure

We request that you do not publicly disclose details without express written consent from Tupl Inc.

10. Policy Review and Updates

This policy will be reviewed and updated annually or as needed.