Vulnerability Disclosure Policy
(Last Updated: September 2026)
Vertical Bridge is committed to the security of our systems and the data entrusted to us. We welcome reports from security researchers and members of the public who discover potential vulnerabilities in our systems, and we appreciate your help in disclosing them responsibly.
Scope
This policy applies to verticalbridge.com and its subdomains. Systems and services not owned or operated by Vertical Bridge are out of scope. If you are unsure whether a system is in scope, contact us before testing.
How to Report
Email CISO@verticalbridge.com with:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof-of-concept, screenshots, or URLs as appropriate)
- Your contact information for follow-up
We will acknowledge your report within 5 business days and keep you informed as we work to validate and remediate the issue.
Conduct
If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will consider your research authorized. We will not pursue or recommend legal action against you for activity conducted in accordance with this policy, and we will work with you if a third party raises concerns about your good-faith research.
Guidelines for Researchers
We ask that you:
- Do not access, modify, or destroy data that does not belong to you; if you encounter sensitive data, stop and report it immediately
- Do not degrade or disrupt our services (no denial-of-service testing)
- Do not use social engineering, phishing, or physical attacks against Vertical Bridge employees, facilities, or infrastructure
- Give us a reasonable opportunity to remediate the issue before disclosing it publicly
Rewards
Vertical Bridge does not operate a paid bug bounty program. We are unable to offer monetary rewards, but we sincerely appreciate the time and effort of researchers who report vulnerabilities to us and are glad to acknowledge your contribution if you wish.
Published at https://verticalbridge.com/security-policy · See also: security.txt