Responsible Disclosure.
How to report a security vulnerability in one of our platforms, and what you can expect from us once you do.
Eight sections, start to finish.
What this program covers.
This program covers security vulnerabilities in SYNE Ratings' public websites, hosted rating platforms, and APIs. It does not cover social engineering of our staff, physical security, or third-party services we do not control.
How to tell us.
Email a detailed report - including steps to reproduce, affected URL or endpoint, and potential impact - to our security team via our Contact Us page marked "Security Report." Please encrypt any sensitive detail where possible.
What you can expect from us.
We will acknowledge your report within two business days, keep you informed of remediation progress, and will not pursue legal action against researchers who act in good faith and within the rules of engagement below.
What good-faith testing looks like.
- Do not access, modify or delete data that isn't your own;
- Do not run automated scanning tools that could degrade service for other users;
- Do not publicly disclose a vulnerability before we've had a reasonable opportunity to remediate it;
- Stop testing and report immediately if you encounter rated-entity confidential data.
What happens after you report.
Reports are triaged by severity, assigned to an owning engineering team, and tracked through to a verified fix. We aim to resolve critical findings within 30 days and will confirm remediation with you directly.
How we credit researchers.
With your permission, we're glad to publicly credit researchers who report a valid, previously unknown vulnerability. We do not currently operate a paid bug bounty program.
Please don't test for these.
Denial-of-service testing, physical intrusion attempts, and social engineering of SYNE staff or rated entities are explicitly out of scope and will not be treated as good-faith research.
Where to send a report.
Submit reports via our Contact Us page marked "Security Report."
Found a vulnerability?
We'd rather hear from you first. Reach our security team directly.