Please ensure Javascript is enabled for purposes of website accessibility

Security Policy

Vulnerability Disclosure Policy

(Last Updated: September 2026)

Vertical Bridge is committed to the security of our systems and the data entrusted to us. We welcome reports from security researchers and members of the public who discover potential vulnerabilities in our systems, and we appreciate your help in disclosing them responsibly.

Scope

This policy applies to verticalbridge.com and its subdomains. Systems and services not owned or operated by Vertical Bridge are out of scope. If you are unsure whether a system is in scope, contact us before testing.

How to Report

Email CISO@verticalbridge.com with:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue (proof-of-concept, screenshots, or URLs as appropriate)
  • Your contact information for follow-up

We will acknowledge your report within 5 business days and keep you informed as we work to validate and remediate the issue.

Conduct

If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will consider your research authorized. We will not pursue or recommend legal action against you for activity conducted in accordance with this policy, and we will work with you if a third party raises concerns about your good-faith research.

Guidelines for Researchers

We ask that you:

  • Do not access, modify, or destroy data that does not belong to you; if you encounter sensitive data, stop and report it immediately
  • Do not degrade or disrupt our services (no denial-of-service testing)
  • Do not use social engineering, phishing, or physical attacks against Vertical Bridge employees, facilities, or infrastructure
  • Give us a reasonable opportunity to remediate the issue before disclosing it publicly

Rewards

Vertical Bridge does not operate a paid bug bounty program. We are unable to offer monetary rewards, but we sincerely appreciate the time and effort of researchers who report vulnerabilities to us and are glad to acknowledge your contribution if you wish.

Published at https://verticalbridge.com/security-policy · See also: security.txt