Samaritan Coordinated Vulnerability Disclosure Policy
Samaritan is committed to maintaining the security of our systems and protecting the privacy of our users. We welcome reports from security researchers and the public regarding potential vulnerabilities in our websites, applications, and services.
Reporting a Vulnerability
If you believe you have discovered a security vulnerability in a Samaritan system, please report it to us promptly by emailing:
SAMARITAN CONTACT
Email: [email protected]
Please include the following information in your report:
A detailed description of the vulnerability
The affected website, application, or service
Steps to reproduce the issue
Proof-of-concept code, screenshots, or other supporting material, if applicable
Your contact information for follow-up
We will acknowledge receipt of your report within a reasonable timeframe and work to investigate and remediate valid issues as quickly as possible.
Guidelines for Responsible Disclosure
To protect our users and systems, we ask that you:
Make every effort to avoid privacy violations, destruction of data, service disruption, or degradation of user experience
Do not exploit the vulnerability beyond what is necessary to demonstrate its existence
Do not access, modify, or delete data that does not belong to you
Do not perform denial-of-service testing, spam, social engineering, or phishing attacks
Do not publicly disclose the vulnerability until Samaritan has had a reasonable opportunity to investigate and remediate the issue
Act in good faith and comply with all applicable laws
Safe Harbor
Samaritan considers activities conducted consistent with this policy to be authorized and will not pursue legal action against individuals who:
Adhere to this policy in good faith
Promptly report vulnerabilities discovered
Avoid harming Samaritan, its users, or its services
Do not violate applicable laws or regulations
If legal action is initiated by a third party against you for activities conducted in accordance with this policy, Samaritan will make it known that your actions were conducted in compliance with this policy.
Scope
This policy applies to all publicly accessible Samaritan-owned websites and web applications unless explicitly excluded.