Responsible Disclosure Policy

Version Number:  1.1

Our website address is: https://brand-aid.io 

Responsible Disclosure Policy - Intro

Trust and communication are cornerstone values at Brand-Aid, a Transatlantic Translations Group company. We collaborate with our customers, partners, and industry to help everyone grow stronger.

Overview

Brand-Aid and its worldwide subsidiaries care about protecting customers’ information. To maintain customers’ trust, we employ physical, technical, and administrative safeguards and value the expertise in the public research community.

Brand-Aid encourages security researchers to promptly report discovered vulnerabilities in accordance with our Responsible Disclosure Policy and Privacy Policy. Brand-Aid reserves all legal rights in the event of noncompliance with these policies.

Reporting Security Vulnerabilities

If you have discovered a security vulnerability, please promptly share the details with Brand-Aid by filling out the form below. Please do not contact Brand-Aid directly (e.g., email, customer support) to report your findings.

Brand-Aid will work with you to validate and respond to submissions, but your initial report should contain sufficient details to allow our teams to reproduce and investigate the issue.

Our Commitment

If you identify a security vulnerability in compliance with this Responsible Disclosure Policy, Brand-Aid commits to:

  • Communicating with you to understand and validate the issue
  • Providing an assessment on the priority of the issue from Brand-Aid’s perspective
  • Working to resolve the finding (if deemed appropriate by Brand-Aid)

Noncompliance

Security researchers must comply with this policy to protect our customers, employees, and business. Brand-Aid will consider any submission non-compliant if it is publicly disclosed without express written consent.

Additionally, any testing must avoid impacting Brand-Aid systems’ confidentiality, integrity, and availability.

Examples of noncompliance include, but are not limited to:

  • Accessing, downloading, or modifying data in an account that does not belong to you.
  • Downloading, collecting, or otherwise retaining the personal information of Brand-Aid customers or employees encountered during your research.
  • Executing, or attempting to perform any “Denial of Service” attack.
  • Interacting with Brand-Aid customers, employees, or business partners (e.g., unsolicited email).
  • Using Phishing or Social Engineering techniques.
  • Attempting to compromise third-party platforms or services that integrate with Brand-Aid systems.
  • Posting, transmitting, uploading, linking to, sending, or storing any malicious software.
  • Requiring monetary compensation in exchange for vulnerability submissions.

Submission Form

All fields are required unless marked optional.