Snapshot 49594
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Your privacy choices Necessary technologies keep this site secure. Analytics and Advertising/Marketing are off unless you choose them. When Global Privacy Control is active, Accept All enables Analytics only and Advertising/Marketing stays off. Vulnerability Disclosure CenterFuze Vulnerability Disclosure Policy Responsible Security Reporting Effective Date: June 16, 2026 • Version 1.0 View Trust CenterContact Legal Responsible security reporting guidelines for customers, partners, and researchers. Purpose CenterFuze values the efforts of security researchers, customers, partners, and members of the security community who help identify potential vulnerabilities. This Policy establishes a process for responsibly reporting potential security vulnerabilities affecting CenterFuze systems and Services. Our Commitment CenterFuze is committed to investigating legitimate security reports, responding in a reasonable timeframe, working collaboratively with researchers, improving platform security, and protecting customer information. Reporting a Vulnerability Potential vulnerabilities should be reported to [email protected]. Reports should include a description of the issue, affected systems, reproduction steps, supporting screenshots or evidence, potential impact, and contact information. Good Faith Research and Testing Guidelines Researchers acting in good faith should avoid privacy violations, service disruption, destruction of data, unauthorized access to customer information, and public disclosure before remediation. Researchers must not access customer accounts or data, modify or destroy data, conduct denial-of-service attacks, deploy malware, or perform social engineering. Prohibited and Out-of-Scope Activities Prohibited activities include data exfiltration, account takeover attempts, credential theft, ransomware, malware, phishing, physical attacks, service disruption, and automated exploitation causing instability. Out-of-scope issues may include social engineering, spam-related findings, missing security headers with no material impact, self-XSS, clickjacking with no meaningful risk, unsupported software, and third-party systems outside CenterFuze control. Investigation and Disclosure CenterFuze may acknowledge receipt, evaluate severity, investigate findings, validate impact, and prioritize remediation. Researchers are asked to maintain confidentiality and allow reasonable remediation time before public disclosure. Safe Harbor and Recognition When acting in good faith and in compliance with this Policy, CenterFuze generally will not pursue legal action solely for activities authorized by this Policy. CenterFuze may, at its discretion, acknowledge researchers but does not currently operate a formal bug bounty unless separately announced. No Compensation and Third-Party Systems Submission does not create an obligation to provide compensation, rewards, payments, or employment opportunities. This Policy applies only to systems owned or controlled by CenterFuze. Third-party services are subject to their own processes. Contact Security reports: [email protected]. Legal matters: [email protected]. CenterFuze appreciates responsible disclosures.