Third Party Index

Snapshot 20832

Document
Security advisories
URL
https://outthink.io/resource-center/trust-security/responsible-vulnerability-disclosure/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
355753 bytes
SHA-256 (raw)
7be36baad152517813f26a7540d5ad7ef8a23f4d2b8f612c018d309726cb4f86
SHA-256 (normalized text)
c5c39374c1da25aeede52be9a312847a062ee88b2dd88c4930531d714d78e7fe

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Learn
Blog
Research labs
Engage & secure podcast
Help
Book a demo
Responsible Vulnerability Disclosure
Last updated: 23 May 2025
Read time: 3 min
Contents
Program SummarySubmission RequirementsRewardsPublic DisclosureHall of Fame
Program Summary
This guide outlines OutThink’s Responsible Vulnerability Disclosure program, for customers and other parties who have potentially found a vulnerability on OutThink’s platform and want to responsibly report it.
If you are a customer with access to support, you can report the vulnerability directly through your normal support channel or contact your Customer Success Representative directly.
Otherwise, please send an email to [email protected].
Submission Requirements
Detail all steps that you followed that make the vulnerability exploitable including any URL’s or code you used. The more information you can provide, the faster we can reproduce and fix the problem.
Please don’t send PDF, DOC, Script or EXE files – we cannot process them. Plain text or images are best.
Any vulnerability can be considered, but particularly those focused around cross-site scripting (XSS), Injection, Cross-site Request Forgery (CSRF), Remote code execution (RCE), data breaches or cookie issues.
Rewards
OutThink has grand plans to introduce a bug bounty program, but we aren’t quite there yet. For the time being, we are happy to name you in our Hall of Fame below. If in the near future we introduce a bug bounty program, we’ll be in touch.
Public Disclosure
Please do not publicly disclose any vulnerability or potential vulnerability before obtaining OutThink’s permission. We will do our best to respond to all legitimate reports and keep you fully informed on progress to resolution.
Hall of Fame
Nothing to see here (yet)!