Responsible Disclosure Policy

Last updated: 6/24/2021

Disclosure Policy

If you believe you have found a security vulnerability in any of our systems or services, we encourage you to report it to us as soon as possible. Please send your report to itsupport@redpeppersoftware.com. We will acknowledge receipt of your report within one week and will work to investigate and resolve the issue. We aim to resolve critical security issues within one month of disclosure.

Exclusions

The following activities are explicitly excluded from the scope of this policy:

  • Denial of service (DDoS) attacks
  • Spamming
  • Social engineering of Red Pepper Software staff or contractors
  • Physical attacks against Red Pepper Software property or data centers

Changes

This policy may be revised from time to time. We encourage you to review this page periodically for the latest information on our responsible disclosure practices.

Contact

For any questions regarding this policy, please contact us at itsupport@redpeppersoftware.com.

Disciplinary Action

Employees who violate this policy may face disciplinary consequences proportional to the nature and severity of the violation, up to and including termination of employment.

Responsibility

The IT Department is responsible for the enforcement and administration of this policy.