Responsible Disclosure
A channel for reporting vulnerabilities in Client Focus operated systems.
1. Scope
This policy covers clientfocusllc.com and Client Focus operated systems.
2. How to report
Include a description, steps to reproduce and the potential impact. Encrypted reporting is available on request.
Send reports to security@clientfocusllc.com.
3. What to expect
Client Focus acknowledges reports within 3 business days, provides status updates and coordinates disclosure with the reporter.
4. Safe harbor
Client Focus will not pursue action against good faith research conducted within this policy's scope. Avoid accessing, modifying or disclosing data belonging to others, and stop testing if you encounter sensitive information.
5. Out of scope
Social engineering, physical attacks, denial of service, third-party services and automated scanner output without demonstrated impact are out of scope.
Talk with Client Focus about your digital asset program.
Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.