Reporting a vulnerability
Email security@baseonesoftware.com. A machine-readable copy of this contact is published at /.well-known/security.txt.
A good report includes:
- the product, URL or app version affected;
- the steps to reproduce the issue, or a proof of concept;
- what an attacker could achieve with it;
- how you would like to be credited, if at all.
What you can expect from us
- We will acknowledge your report and tell you whether we can reproduce it.
- We will keep you informed while we work on a fix.
- We will credit you when the issue is resolved, if you want us to.
Good-faith research
We will not pursue legal action against researchers who act in good faith and follow this policy. Acting in good faith means you:
- test only against your own accounts and data;
- avoid accessing, changing or deleting other people's data, and stop and report if you encounter any;
- do not degrade the service: no denial of service, spam or automated scanning at volume;
- do not use social engineering or physical attacks against our staff or infrastructure;
- give us reasonable time to fix the issue before disclosing it publicly.
Out of scope
- Services run by third parties, such as app stores, hosting platforms and payment processors. Please report those to the provider.
- Findings from automated tools with no demonstrated impact.
- Missing security headers or best-practice suggestions with no practical exploit.
Phishing and impersonation
Email from Base One comes from an address ending in @baseonesoftware.com. We never ask for passwords, payment card numbers or one-time codes by email. Forward anything suspicious to security@baseonesoftware.com.