Last updated: October 12, 2022
InsideTracker (Segterra) Security is continually adapting to the changing cybersecurity landscape and to stay ahead of bad actors and threats to our systems and applications. However, keeping our customer and employee information safe is not achieved by technology alone – it takes alerts from employees, customers and partners, who know how to recognize and report issues.
InsideTracker (Segterra)’s Responsible Disclosure program allows our customers and partners to submit vulnerabilities that they may find on any public-facing websites or applications owned, operated or controlled by InsideTracker (Segterra). Any services provided or hosted by a third-party are not eligible. An application or system vulnerability is a system flaw or weakness that could be exploited to compromise the security of an application or system. If you are unsure if the vulnerability you are reporting meets this criteria, please contact us info_security@insidetracker.com
Vulnerability reports can be emailed to info_security@insidetracker.com
The information you provide will be reviewed by members of InsideTracker (Segterra) Security Team. Your report should include the following information:
A detailed report is crucial to the team to remedy your submitted vulnerability. If the above requirements have been met, we will confirm receiving your report within three business days. The information you provide will be used to correct vulnerabilities and improve the security of our applications and infrastructure. A member of the Security team will reach out to you if additional details are needed.
While confirming the vulnerability, InsideTracker (Segterra) will attempt to keep you informed of the status on a reasonable basis.
By submitting your vulnerability disclosure to InsideTracker (Segterra) you agree that you will keep information related to the vulnerability confidential and not disclose the vulnerability to any third-party unless InsideTracker (Segterra) has provided you with written authorization to do so. Submission of this vulnerability report provides your permission for InsideTracker (Segterra) to use, create derivatives of, disclose, or modify any information that you have provided.
InsideTracker (Segterra) assumes no obligation or responsibility for providing financial or other types of compensation to you for reporting this vulnerability.
Compliance with this program requires that you read the following carefully and abide by all of the specific scoping guidelines. Questions regarding these restrictions can be sent to: info_security@insidetracker.com
Do not perform any of the following actions:
STOP your activities and notify us immediately if you encounter any of the information below while testing within the scope of this program:
Responsible disclosure reports must be submitted by persons who are 13 years or older, following The Children’s Online Privacy Protection Act (COPPA) guidelines.
You must comply with all applicable laws and regulations. InsideTracker (Segterra) does not permit, allow, or authorize any actions that are inconsistent with this program. InsideTracker (Segterra) reserves all legal rights in the event of noncompliance with these guidelines.
If you make a good faith effort to comply with this program, we will work with you to understand and quickly resolve the issue, and InsideTracker (Segterra) will not recommend legal action in relation to your submitted vulnerability.
InsideTracker (Segterra) may modify this program and associated terms at any time.