Responsible Disclosure Policy

At Eye, the security of our systems is a top priority. While we strive to maintain a high level of security, we recognize that no system is ever completely secure. If you discover a vulnerability, we encourage you to report it to us responsibly.

We run a Vulnerability Disclosure Program (VDP) on HackerOne. You can submit your findings directly through security@eye.security. For high and critical severity vulnerabilities, we send exclusive Eye swag as a token of appreciation.

Safe Harbor

We welcome and respect the work of security researchers. We consider activities conducted in good faith and in accordance with this policy to be authorised conduct, and we will not take legal action against you.

If a third party initiates legal action against you in connection with activities covered by this policy, we will confirm that your actions were conducted in compliance with this policy. Please note, however, that:

· We cannot authorize security research on third-party infrastructure

· Third parties are not bound by this safe harbor protection

Scope

This policy applies to all Eye-owned or managed systems and services that are accessible via the internet. This includes, but is not limited to, the following assets:

agent.eye.security

api.app.eyeunderwriting.eu

api.control.eye.security

api.integrations.eye.security

api.portal.eye.security

app.eyeunderwriting.eu

apply.underwriting.eye.security

checker.apps.eye.security

control-plane.eye.security

eye-auth.apps.eye.security

guardpost.eye.security

mdr-dashboard.apps.eye.security

onboarding.eye.security

portal.eye.securityresearch.eye.security

tiramisu.eye.security

with-coffee.tiramisu.eye.security

Out of scope:

If you're unsure whether an asset is in scope, please contact us at security@eye.security.

Out-of-scope Vulnerabilities

The following are considered out of scope and will not be eligible for recognition:

Reporting Guidelines

Please report vulnerabilities via our HackerOne VDP or email us at security@eye.security (PGP available on our website).

Reports should include:

Research Guidelines

We ask that you:

What You Can Expect from Us

Questions

Questions regarding this policy may be sent to security@eye.security. We also invite you to contact us with suggestions for improving this policy.