Third Party Index

Snapshot 22059

Document
Security page
URL
https://featureupvote.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
48048 bytes
SHA-256 (raw)
4176d4c743c8e39151ea3afe6d3fa1a773eeafc7b23a3ec953396f9b3f2045fc
SHA-256 (normalized text)
59928438aea5c37cdd04d81c1f142f90d7cc08f754cabab99df6d7d95cc52178

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
Many companies say they take security seriously. In our case, we’d like to demonstrate this with concrete information.
SOC 2 coming soon: We are actively preparing for a SOC 2 Type II audit. Our “trust centre” will be available soon. Contact [email protected] for more info.
Upon request, we can provide a “Letter of Engagement” from our compliance platform.
Security Audit
We regularly commission independent security professionals to audit our security. We implement any findings and recommendations as a matter of priority.
EU General Data Protection Regulation (GDPR)
As we are based in Spain, which is in the European Union, we are regulated by the EU General Data Protection Regulation (GDPR). We abide fully by the EU GDPR. Read more about our GDPR compliance.
Employee Access
Wherever possible, we use two factor authentication (2FA) to restrict access to our IT infrastructure and to customer data.
Each team member is supplied with a password manager application to ensure that we all use strong, unique passwords for each service we use.
When an individual ceases working with us, we revoke their access to all services.
Infrastructure
The Feature Upvote application runs on Amazon’s AWS infrastructure. We follow AWS’s best practice guides. We regularly audit our use of AWS. We regularly check our server logs for suspicious activity.
Our database (MySQL hosted on AWS) uses encryption at rest and in transit. The encryption algorithm is AES-256-GCM. Encryption is enforced; access without encryption is not possible.
We enforce TLS 1.2+ on all web traffic to our app.
AWS offers a choice of geographic regions. Our AWS region is Ireland, a European Union member state. We store production data solely within the European Union.
Our web application only accepts and transmits traffic over HTTPS.
Backups
We take frequent backups and regularly ensure that a recent backup can be restored. Access to backups is guarded with a combination of 2FA, password managers, encryption at rest, and tight access rules.
Credit Card Data
At no time do we store your credit card details on our servers. Our payment processor, Stripe, handles payment processing on our behalf. Stripe ensures that all relevant compliance, such as PCI, is met.
None of our staff, including management, have access to your credit card info.
SOC 2 / ISO 27001
We are actively preparing for a SOC 2 Type II audit. Our “trust centre” will be available soon.
Upon request, we can provide a “Letter of Engagement” from the compliance platform we are using for SOC 2 audit preparation.
At this time we do not have ISO 27001 certification.
Got questions about our security? Ask us at [email protected]
Responsible Disclosure
We welcome whitehat security researchers and will gratefully receive reports of suspected security problems. We don’t offer bug bounties.
We ask you to refrain from the following:
attempts to modify or destroy data
attempts to interrupt or degrade the services we offer to our customers
attempts to execute a Denial Of Service (DOS) attack
attempts to access a user’s account or data
violating any applicable law
We don’t offer bug bounties
The first sign that you haven’t read our security page before reporting what you believe to be an issue is that you ask about our bug bounty program. To repeat, We don’t have a bug bounty program.
However we do acknowledge contributions here on our site.
Only the first researcher to report a specific qualifying issue is eligible for acknowledgement. Whether an issue is a qualifying issue, as well as eligibility for acknowledgement, are decisions taken by us in our discretion.
We reserve the right to cancel this program at any time without notice.
Guidelines
In order to qualify for acknowledgement, please follow these guidelines when reporting issues:
Report security issues via our security email address. The address is [email protected].
Do not use automated scripts/tools without prior approval and scheduling. We understand the value of automated vulnerability detection scripts and software, but we ask you not to run automated scans of any kind without scheduling it with us in advance.
Expect a followup within 24 hours on business days. We do our best to respond quickly. We take every report seriously, and if you don’t hear back promptly, it doesn’t mean that we’re ignoring it. It means that we didn’t receive it. If you don’t hear back within 24 hours on a business day, please drop us a reminder via our support email address, and we’ll make sure that it hasn’t slipped through the cracks.
Only test Feature Upvote systems. Systems hosted by third parties do not qualify for acknowledgement.
Provide steps to reproduce the problem in our systems. Providing generic background information about a class of vulnerability without specific details about how our systems are vulnerable does not qualify for acknowledgement.
Please do not share your research or findings publicly until we’ve had time to research and release a fix for the problem.
Vulnerabilities eligible for acknowledgement
Arbitrary redirects
Authentication or authorization flaws
Circumventing of platform and/or privacy permissions
Clickjacking
Cross-site scripting (XSS)
Cross-site request forgery (CSRF)
Privilege escalation
Server-side code execution (RCE)
SQL injection
Ineligible vulnerabilities
Denial of Service (DoS)
Issues with outdated or unpatched browsers
Minor information disclosures (ex. server software/version)
Spamming
Vulnerabilities in third-party web sites and tools that integrate with Feature Upvote
Vulnerabilities that require a potential victim to install non-standard software or otherwise take active steps to make themselves be susceptible to attack
How to report issues
Report security vulnerabilities to [email protected]. Once we’ve received your email, we’ll work with you to make sure that we completely understand the scope of the problem and keep you informed as we work on the solution.
Acknowledgements
We appreciate your help to find and resolve security issues responsibly. The following have worked to help us keep Feature Upvote safe and secure for everyone. Thank you.
Hamza Khan
Ali Khan
Hsu Myat Noe
Dinesh Kumar