Responsible Disclosure Policy
Security Vulnerability Reporting
Last Updated: April 4, 2026
1. Introduction
Infinity Cloud System LIMITED ("we," "us," or "our") is committed to ensuring the security and privacy of our systems, services, and customer data. We value the security research community and welcome responsible disclosure of potential security vulnerabilities.
This Responsible Disclosure Policy outlines our commitment to working with security researchers and provides guidelines for reporting security issues to us in a responsible manner.
2. Our Commitment
We commit to:
- Respond to your report promptly and keep you informed throughout the process
- Work with you to understand and validate the reported issue
- Acknowledge your contribution to improving our security
- Not pursue legal action against researchers who comply with this policy
- Treat your report confidentially and not share your personal information without permission
- Keep you informed of our progress in addressing the vulnerability
3. Scope
3.1 In Scope
This policy applies to security vulnerabilities in:
- Our website: infinitycloudsystem.com (and all subdomains)
- Our web applications and services
- Our APIs and integrations
- Our infrastructure and systems
- Client-facing applications and platforms
3.2 Out of Scope
The following are outside the scope of this policy:
- Third-party services and applications (e.g., Stripe, hosting providers)
- Social engineering attacks (phishing, vishing, etc.)
- Physical security issues
- Denial of Service (DoS/DDoS) attacks
- Spam or social media account issues
- Issues requiring physical access to our facilities
4. Reporting Guidelines
4.1 How to Report
To report a security vulnerability, please email us at:
Security Email: finance@infinitycloudsystemlimited.com
Subject Line: "Security Vulnerability Report"
Encryption: PGP encryption encouraged for sensitive reports
4.2 What to Include
Please provide the following information in your report:
- Description: Clear description of the vulnerability
- Impact: Potential impact and severity assessment
- Steps to Reproduce: Detailed steps to reproduce the issue
- Proof of Concept: Code, screenshots, or videos demonstrating the vulnerability
- Affected Systems: URLs, endpoints, or systems affected
- Your Contact Information: Name and email for follow-up
- Disclosure Timeline: Your preferred disclosure timeline (if any)
4.3 Report Quality
High-quality reports include:
- Clear, concise description of the vulnerability
- Reproducible steps with minimal complexity
- Assessment of potential business impact
- Suggestions for remediation (optional but appreciated)
- Evidence that demonstrates the vulnerability without causing harm
5. Safe Harbor
We consider security research and vulnerability disclosure activities conducted in accordance with this policy to be:
- Authorized: Conducted with our permission
- Lawful: Not in violation of applicable laws (including the Computer Misuse Act 1990)
- Valuable: A contribution to our security posture
We will not pursue legal action against researchers who:
- Comply with this policy and applicable laws
- Make good faith efforts to avoid privacy violations, data destruction, and service disruption
- Report vulnerabilities promptly and responsibly
- Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
6. Rules of Engagement
6.1 Permitted Activities
When testing for vulnerabilities, you may:
- Use your own test accounts and data
- Perform automated scanning with reasonable rate limits
- Test for common vulnerabilities (XSS, SQLi, CSRF, etc.)
- Analyze client-side code and APIs
- Test authentication and authorization mechanisms
6.2 Prohibited Activities
You must NOT:
- Access, modify, or delete data belonging to other users
- Perform actions that could harm our services or users (DoS, data destruction)
- Exploit vulnerabilities for personal gain or to harm others
- Access or attempt to access accounts you do not own
- Perform social engineering attacks against our employees or customers
- Conduct physical attacks against our facilities
- Violate privacy laws or regulations
- Publicly disclose vulnerabilities before we have had time to address them
6.3 Testing Limits
Please conduct testing responsibly:
- Limit automated scanning to reasonable rates to avoid service disruption
- Use only test accounts you create yourself
- Stop testing immediately if you encounter user data or sensitive information
- Do not attempt to pivot to other systems or networks
- Respect system resources and bandwidth limitations
7. Our Response Process
7.1 Initial Response
Upon receiving your report, we will:
- Acknowledge receipt within 3 business days
- Assign a tracking number for reference
- Provide an initial assessment of severity and impact
- Request additional information if needed
7.2 Investigation and Validation
We will:
- Investigate and validate the reported vulnerability
- Determine the scope and impact
- Develop and test a fix
- Keep you informed of our progress
7.3 Resolution Timeline
Our target timelines for resolution:
- Critical: 7 days
- High: 30 days
- Medium: 60 days
- Low: 90 days
These are target timelines and may vary depending on complexity. We will communicate any delays.
7.4 Disclosure
We follow coordinated disclosure practices:
- We will work with you to agree on a disclosure timeline
- We request a minimum of 90 days before public disclosure
- We may publicly acknowledge your contribution (with your permission)
- We will notify you before publishing any security advisories
8. Recognition
We value the contributions of security researchers. With your permission, we may:
- Publicly acknowledge your contribution in our security advisories
- Include your name in our security hall of fame (if we establish one)
- Provide a letter of appreciation for your CV or portfolio
We do not currently offer monetary rewards (bug bounties), but we deeply appreciate responsible disclosure and will acknowledge your efforts.
9. Confidentiality
We will:
- Treat your report as confidential
- Not share your personal information without your permission
- Only share technical details with those who need to know to address the issue
- Respect your wishes regarding public acknowledgment
We ask that you:
- Keep vulnerability details confidential until we have addressed the issue
- Do not share information about the vulnerability with others
- Coordinate with us on any public disclosure
10. Legal Considerations
10.1 UK Computer Misuse Act 1990
The UK Computer Misuse Act 1990 criminalizes unauthorized access to computer systems. This policy provides authorization for security research conducted in accordance with these guidelines.
10.2 Data Protection
If you encounter personal data during your research:
- Do not access, copy, or retain the data
- Report the exposure immediately
- Delete any inadvertently accessed data
- Comply with UK GDPR and Data Protection Act 2018
10.3 Limitations
This policy does not:
- Grant permission to violate laws or regulations
- Create any contractual relationship or obligation
- Waive any legal rights we may have
- Apply to malicious or harmful activities
11. Third-Party Services
If you discover vulnerabilities in third-party services we use (e.g., Stripe, hosting providers):
- Report them directly to the third-party vendor
- Inform us if the vulnerability affects our implementation or customers
- Follow the third party's responsible disclosure policy
12. Policy Updates
We may update this policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.
13. Contact Information
For security vulnerability reports or questions about this policy:
Security Team
Email: finance@infinitycloudsystemlimited.com
Subject: "Security Vulnerability Report"
Company: Infinity Cloud System LIMITED
Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company Number: 17131879
Thank You:
We appreciate the security research community's efforts to help us maintain the security and privacy of our systems and customers. Your responsible disclosure helps us protect our users and improve our security posture. Thank you for working with us to keep our services secure.