Coordinated vulnerability disclosure policy
Effective date: 02/01/2025
At easee, safeguarding the security of our systems is one of our highest priorities. Despite our efforts to maintain robust security measures, vulnerabilities may still exist.
If you identify a potential vulnerability, we’d greatly appreciate your assistance in addressing it promptly. Your efforts will help us better protect our clients, employees, customers, infrastructure, intellectual property, and products.
We kindly request that you:
- – Report your findings by sending an email to security@easee.online. To ensure the sensitive information remains secure, please encrypt your message using our PGP key.
- – Refrain from taking advantage of the vulnerability, such as by downloading excessive data beyond what is necessary to demonstrate the issue or by altering or deleting other people’s data.
- – Avoid sharing information about the vulnerability with others until it has been resolved.
- – Conduct your research responsibly and ensure no harm is caused to easee. This includes avoiding social engineering, spamming, DoS attacks, or any actions affecting physical security.
- – Provide enough detail for us to replicate the issue and resolve it swiftly. Typically, this includes the IP address or URL of the affected system and a clear description of the vulnerability. For more complex issues, additional information such as the requests sent or responses received may be needed.
Our Commitment to You:
- – We will acknowledge your report within three business days, providing an evaluation and an estimated timeline for resolution.
- – If you adhere to these guidelines, we assure you that no legal action will be taken against you for your report.
- – Your report will be treated with the utmost confidentiality, and your personal information will not be shared with third parties without your consent.
- – We will keep you updated on the progress of resolving the issue.
- – In any public communication about the resolved issue, we will credit you for the discovery, unless you request otherwise.
- – Please note that we do not offer monetary rewards for reporting vulnerabilities.
We are committed to addressing issues as quickly as possible and would be glad to work with you on any final publication about the vulnerability once it has been resolved.
© 2025 easee Inc. All rights reserved.