Vulnerability disclosure policy
Last updated: 13 August 2026
Reporting a vulnerability
If you believe you have found a security vulnerability in the AssetObserve service, please report it to contact@assetobserve.com. This page is the policy referenced by our security.txt record at /.well-known/security.txt.
Please include enough detail for us to reproduce the issue: the affected URL or component, the steps you took, what you observed, and what you expected. A proof of concept, request log, or screenshot helps. Let us know if you would like to be credited.
What we commit to
- We acknowledge a report within five working days.
- We tell you our assessment of the severity and our intended remediation timeline once we have reproduced the issue.
- We keep you informed while we work on a fix, and we tell you when it is deployed.
- We do not pursue legal action against a finder who follows this policy in good faith.
We do not currently operate a paid bug bounty. Credit in our release notes is available on request.
Scope
In scope: the AssetObserve web application, its public API, its agent ingest endpoints, and the customer-side agent we distribute.
Out of scope:
- Findings against a customer workspace that is not your own, or against systems belonging to a customer
- Denial-of-service testing, load testing, and any test that degrades the service for other users
- Social engineering, phishing, or physical attacks against our staff or providers
- Reports produced only by an automated scanner, with no demonstrated impact
- Missing hardening headers or configuration recommendations with no demonstrated exploit path
- Vulnerabilities in third-party services we consume, which should be reported to that provider
Testing guidelines
Please test only against your own account or workspace, or against the public demo environment. Use the minimum interaction needed to demonstrate the issue. Do not access, modify, delete, or retain personal data belonging to anyone else; if you encounter such data, stop and tell us in the report. Do not publish details of an unfixed issue.
Our own product
AssetObserve is a read-only assessment tool by design: it does not exploit, brute-force, modify, or disable the systems it inventories, and must only be pointed at systems the operator is authorized to assess. A report that AssetObserve can be used against an unauthorized network describes the operator's misuse rather than a defect, but we do want to hear about anything that lets one workspace observe another's data.
Placeholder notice
Confirm the acknowledgement window, the remediation timelines, the safe-harbour wording, and whether a demo environment is offered for testing, and have the safe-harbour paragraph reviewed by legal counsel, before this policy is published.
Contact: contact@assetobserve.com