Legal
Security & Vulnerability Disclosure
How to report security vulnerabilities in our Website or systems responsibly.
We appreciate reports that help us protect customers and systems. This channel is for technical security vulnerabilities (for example authentication flaws, injection, or sensitive data exposure). For phishing emails, use Reporting Suspicious Emails instead.
1. Scope
In-scope examples include vulnerabilities affecting vcloudchoice.com properties, customer/business portals, and related APIs that could lead to unauthorized access or data exposure. Out-of-scope examples include social engineering of staff, physical attacks, and denial-of-service testing without prior written approval.
2. How to Report
Email [email protected] with the subject “Security Vulnerability Report.” Include a clear description, affected URL/endpoint, steps to reproduce, potential impact, and your contact details. Do not include real customer data in proof-of-concept payloads.
3. Good-Faith Rules
Act in good faith: do not exploit the issue beyond what is needed to demonstrate it, do not access or modify data that is not yours, and give us a reasonable time to investigate before public disclosure. We will work to acknowledge reports and remediate confirmed issues.
