/Data? Trusted./
Security at ColoradoRiver Software
We are committed to protecting your data and maintaining strong security practices. Our infrastructure is built on industry-standard security practices to protect the integrity and confidentiality of your information. We regularly review our security posture to ensure we are meeting the highest standards.
Security & Vulnerability Reporting
At ColoradoRiver Software, the security of our systems and the protection of our customers’ data is our top priority. We value the contributions of the security research community and welcome reports of vulnerabilities. This policy applies to ColoradoRiver Software products, services, and publicly accessible infrastructure.
How to Report an Issue
If you believe you have discovered a security vulnerability in a ColoradoRiver Software product, application, or infrastructure, please contact our security team immediately.
What to include: Please provide a detailed description of the issue, steps to reproduce it, and any supporting evidence (logs, screenshots, or code).
Responsible Disclosure Policy
To ensure the safety of our users, we ask that you act in good faith when researching and reporting vulnerabilities.
Do not attempt to access or modify data that does not belong to you.
Do not execute Denial of Service (DoS) attacks or disrupt our services.
Do not use social engineering or phishing against our employees.
Do give us reasonable time to investigate and mitigate the issue before making any information public.
Out of Scope Vulnerabilities
Please do not report the following unless you can demonstrate clear security impact:
Missing email best practices (SPF/DKIM/DMARC).
Clickjacking on pages with no sensitive actions.
Self-XSS (Self-Cross Site Scripting).
Our Commitment
If you report a vulnerability in accordance with this policy, ColoradoRiver Software commits to working with you to understand and resolve the issue promptly. We will not pursue legal action against researchers who act in good faith and adhere to these guidelines.