Vulnerability Disclosure Policy

Objective

The objective of this Vulnerability Disclosure Policy (VDP) is to establish a clear, transparent, and secure process for the reporting and resolution of security vulnerabilities discovered in Infinite’s systems, applications, and infrastructure.

Scope

This VDP applies to security vulnerabilities discovered in the digital assets owned, operated, or maintained by Infinite, including but not limited to:

Definition

Security researchers are individuals or organizations who investigate systems, software, or networks to identify potential security vulnerabilities. They do this not to exploit weaknesses, but to responsibly report them so developers can fix the issues before malicious actors discover them.
They may include:

Security researchers must not:

Security researchers should:

Reporting Vulnerabilities to Infinite

Security researchers can report vulnerabilities related to Infinite to Vulnerability-Disclosure@infinite.com.

Submission(s) must include:

Security researchers may submit reports anonymously, or they may provide contact information, and any preferred methods or times of day to communicate, as they see fit.

Resolution

When a vulnerability is reported in good faith and in line with this policy:
If a security researcher believes others should be informed of the vulnerability before the corrective actions are implemented, Infinite requires them to coordinate in advance.

Rewards

Infinite may offer reward or recognition for vulnerability reports that have a significant business impact on its customers, products, or services.
Eligibility for recognition is determined by calculating the internal severity of a finding against the potential impact to Infinite and its customers. Infinite reserves the right, in sole and absolute discretion, to determine vulnerability qualification for a reward or recognition.

VDP Program

This policy enables Infinite to operate a vulnerability disclosure program that encourages security researchers to report vulnerabilities responsibly, thereby supporting Infinite in effectively resolving the identified issues.

Download

This field is for validation purposes and should be left unchanged.