GroupMap Responsible Disclosure
Our customers trust us to keep their data secure and confidential. We take security seriously and work constantly to ensure that trust is well-founded. Have something to report? Please reach out to us at security@groupmap.com
Responsible disclosure
We welcome reports from anyone who practises responsible disclosure and complies with our policies and terms of service. Please avoid automated testing and only perform security testing with your own data. Please do not disclose any information regarding vulnerabilities until we have fixed them. We may, at our sole discretion, offer recognition for high-quality, impactful reports that demonstrate a genuine security risk.
You can report vulnerabilities by contacting security@groupmap.com. Please include a proof of concept. We will respond as quickly as possible to your submission and won’t take legal actions if you follow the rules.
Coverage
- *.groupmap.com
Exclusions
- ww1.groupmap.com
- ww2.groupmap.com
- ww3.groupmap.com
- www.groupmap.com
- help.groupmap.com
- feedback.groupmap.com
- mail.groupmap.com
- status.groupmap.com
- track.groupmap.com
- at.groupmap.com
- *.eu.groupmap.com
- *.common.groupmap.com
- *.internal.groupmap.com
- *.sandbox.groupmap.com
Accepted vulnerabilities are the following
- Cross-Site Scripting (XSS)
- Open redirect
- Cross-site Request Forgery (CSRF)
- Command/File/URL inclusion
- Authentication issues
- Code execution
- Code or database injections
Out of scope
- Account/email enumerations
- Denial of Service (DoS)
- Attacks that could harm the reliability/integrity of our business
- Spam attacks
- Clickjacking on pages without authentication and/or sensitive state changes
- Mixed content warnings
- Lack of DNSSEC
- Content spoofing / text injection
- Timing attacks
- Social engineering
- Phishing
- Insecure cookies for non-sensitive cookies or 3rd party cookies
- Vulnerabilities requiring exceedingly unlikely user interaction
- Exploits that require physical access to a user’s machine
Our thanks go to the following security researchers: