Responsible Disclosure of Security Vulnerabilities Policy
SystemOne is committed to maintaining the security of our systems and our customers’ data. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.
Disclosure Policy
- Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
- Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
Exclusions
We'd like to ask you to refrain from:
- Any activity that can potentially or actually cause harm to SystemOne, our customers, or our employees
- Storing, sharing, compromising or destroying SystemOne or customer data. If Personally Identifiable Information (PII) is encountered, you should immediately halt your activity, purge related data from your system, and immediately contact SystemOne.
- Any automated scanning or testing
- Denial of service attacks
- Spamming
- Social engineering (including phishing) of SystemOne staff or contractors
Please reach out to security@systemone.id to report any critical issues you may discover.
Once your report is submitted, SystemOne commits to acknowledge receipt within two business days and will keep you reasonably informed of the status of any validated vulnerability that you report through this program.
Thank you in advance for your submission.