Vulnerability Disclosure Policy
1. About this document
This document outlines the Vulnerability Disclosure Policy for Tupl, Inc., a Delaware corporation, hereinafter "Tupl". It details how to report potential security vulnerabilities in Tupl systems and services and includes guidelines for ethical hacking, the scope of in-scope and out-of-scope reports, and our commitment to legal protection and confidentiality for researchers. This policy ensures that vulnerabilities are reported and addressed responsibly.
If you believe you have found a security vulnerability on one of Tupl web sites or in Tupl apps, we thank you in advance for letting us know right away. We will investigate all legitimate reports and strive to address any security issues promptly.
This policy must be read and understood before any security research is conducted or any reports are submitted. Compliance with this policy is required to ensure that security vulnerabilities are reported and handled in a responsible manner, protecting both the researchers and Tupl.
2. Rewards
Tupl does not currently offer a reward program; thus, there will not be any compensation, reward or public recognition for submittal of potential vulnerabilities. By submitting a vulnerability, you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against Tupl related to your submission.
3. Authorization
If you make a good faith effort to comply with this policy during your security research, Tupl will consider your research to be authorized, will work with you to understand, and resolve the issue quickly, and Tupl will not recommend or pursue legal actions related to your research.
4. Guidelines for operating in good faith
Under this policy, "research" means activities in which you: Notify us as soon as possible after discovering a real or potential security issue; Avoid disruptive actions against Tupl systems; Keep the information related to the discovered vulnerability confidential; Avoid privacy violations or any destruction, modification or exfiltration of Tupl data; Use exploits only to the extent necessary to confirm a vulnerability's presence; Do not submit low-quality reports; Once you have established that a vulnerability exists or encounter any sensitive data, you must stop your test, notify us immediately, and not disclose this data to anyone else.
5. Out of Scope Reports and Ineligible Findings
The following vulnerabilities are out of scope:
- Spam or social engineering techniques
- Network denial of service (DoS or DDoS) tests
- Brute force credential compromise
- Theoretical vulnerabilities requiring unlikely user interaction
- Content spoofing and text injection
- Broken link hijacking, tabnabbing
- Attacks requiring physical access
- Self-exploitation
- Theoretical vulnerabilities with no demonstrated security impact (including Clickjacking on non-sensitive pages, CSRF on non-sensitive forms, Permissive CORS without impact, Software version disclosure, CSV injection, Open redirects without additional impact, Optional security hardening like SSL/TLS configs, lack of SSL Pinning, lack of jailbreak detection, cookie handling, CSP opinions, optional email security features, rate limiting issues)
- Vulnerabilities requiring hazardous testing
6. Systems in Scope
This policy applies to:
- *.agroadvisor.com
- *.tupl.com
- *.tupl.io
- *.tuplos.com
Any service not listed is excluded from scope.
7. Contact Information
To disclose a potential vulnerability, please email: cybersecurity.support@tupl.com. We will not share your name or contact information without express permission.
8. Response Time
We commit to acknowledging receipt of your vulnerability report within 5 business days and will keep you informed about the progress.
9. Public Disclosure
We request that you do not publicly disclose details without express written consent from Tupl Inc.
10. Policy Review and Updates
This policy will be reviewed and updated annually or as needed.