Third Party Index

Snapshot 51294

Document
Security advisories
URL
https://insites.com/legal/vulnerability-disclosure/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
114638 bytes
SHA-256 (raw)
384490c954df59804abd8e479db0082768c5d3c35d3d65d1895cb151371f23b8
SHA-256 (normalized text)
77be2afc633392ea98a5596cd82ea01b870d75d8d0f70b50da765e50c3773426

Normalized text

Scripts and page chrome removed; this is what change detection compares.

See how any business shows up in ChatGPT, Gemini and more
Run a free AI visibility audit
Legal
Vulnerability Disclosure
Overview
Insites is committed to maintaining the security, integrity and availability of our systems, and to protecting our customers' data.
We do not operate a bug bounty programme, and we do not invite, commission or consent to security testing of our platform. This policy exists so that if you become aware of a vulnerability affecting Insites, there is a clear and proper way to tell us about it, and so that the limits we expect to be respected are set out in advance.
It explains what a report must contain, what we will do with one, and what we will not accept.
Permission and Safe Harbour
This policy is not permission to test. Nothing in it authorises you to access, probe, scan, disrupt or interfere with our systems, our customers' data, or any account that is not your own. Activity outside this policy is unauthorised, and we reserve all rights and remedies in respect of it.
Where you report a vulnerability to us in good faith and you have stayed within the limits below, we will not pursue legal action against you in respect of that report. This applies where you:
Acted in good faith, with no intent to extort, disrupt, or profit.
Stopped as soon as you had enough to demonstrate the issue, and went no further.
Accessed no more data than was strictly necessary, and did not retain, copy or share any of it.
Caused no degradation to our service and no harm to our customers.
Reported the issue to us promptly and privately, and kept it confidential.
This protection is limited to the conduct described above. It does not extend to anything beyond it, and it does not apply where these conditions are not met.
If a third party brings legal action against someone who complied with this policy in full, we will confirm that their report was made in accordance with it.
Scope
We will accept reports about:
Public-facing web applications operated by Insites.
Domains owned and controlled by insites.com.
Public APIs and documented endpoints.
Customer-facing dashboards and services.
Authentication and authorisation mechanisms.
Listing an asset here describes what we are willing to receive a report about. It is not permission to test that asset.
The following are never acceptable and fall outside this policy entirely:
Social engineering or phishing targeting our employees, contractors, or customers.
Physical security testing.
Denial-of-service attacks, stress testing, or anything that degrades performance for others.
Automated scanning that generates significant traffic.
Testing against third-party services not owned or operated by Insites, including the websites our customers submit for analysis.
Accessing, modifying or exfiltrating another user's data.
How to Report a Vulnerability
Email security@insites.com.
Your report must contain enough detail for us to reproduce the issue. As a minimum, tell us:
The affected URL, API or component.
What the vulnerability is.
Step-by-step instructions to reproduce it.
What someone could actually do with it, and why that matters.
Any supporting evidence, such as proof-of-concept code, screenshots or logs.
Reports without that detail will not be answered. In particular, we do not respond to:
Messages stating that a vulnerability exists without saying what it is.
Requests to agree a reward, or to confirm a bounty, before details will be shared.
Raw output from an automated scanner, sent without analysis.
Reports of findings with no demonstrated security impact, such as missing headers or configuration preferences.
We will not enter into any negotiation about payment in exchange for details of a vulnerability.
Please keep the issue confidential and do not disclose it publicly until we have had a reasonable opportunity to remediate it.
What We Will Do
Where a report meets the requirements above, we aim to:
Acknowledge it within five working days.
Triage and validate the issue.
Tell you how we have assessed its severity and what we intend to do about it.
Remediate confirmed vulnerabilities on a timescale proportionate to their severity and to the risk they present.
These are aims rather than commitments, and they do not apply to reports that fall short of the requirements above.
Coordinated Disclosure
We expect a vulnerability to remain confidential until remediation is complete and our customers are protected. Once an issue is resolved we are willing to discuss whether and when it can be described publicly. We do not accept disclosure deadlines set unilaterally, and publishing before we have remediated falls outside this policy.
Rewards
We do not operate a bug bounty programme. We may choose to acknowledge a researcher who has made a genuinely useful report, entirely at our discretion. Nothing in this policy creates any expectation or entitlement to payment, recognition or reward.
Limits We Expect to Be Respected
If you do become aware of a vulnerability:
Do nothing that affects the availability or performance of the service.
Do not access or retain sensitive customer data.
Stop immediately and tell us if you encounter customer data unintentionally.
Do not attempt to create or obtain an account. Accounts are provisioned to our customers, and there is no self-service sign-up. If you are a customer, stay within your own account and your own data.
Do not attempt lateral movement, privilege escalation, or persistence beyond what is needed to establish that the issue is real.
Legal Terms
By reporting a vulnerability to us, you confirm that you have complied with all applicable laws and regulations, that you have not exploited the issue for financial gain or any malicious purpose, and that the detail you have provided is accurate.
Reporting an issue to us does not entitle you to any payment, and does not transfer to you any right in our systems or data.
Updates to This Policy
We may update this policy from time to time to reflect changes in our security practices. The version on this page is the current one.
Contact
Security team: security@insites.com.
Platform audits
SEO & AEO Audit
Local SEO
Speed & Performance
Accessibility
Compliance
Content & UX
Ads Audit
Social Media Audit
Rank Tracking
All Audits
Features
AI Visibility Monitoring
Customise Your Audit
White-Label Audits
Bulk Website Auditing
Lead Signals
Competitor Audit
Local Grid
AI Keyword Planner
Paige Agent
AI Email Generator
Sharing & Export
Integrations
All Integrations
MCP Server
REST API
Webhooks
Salesforce
HubSpot
Zapier
Duda
Alternatives
marketgoo Alternative
BuzzBoard Alternative
WooRank Alternative
SE Ranking Alternative
Local Falcon Alternative
BrightLocal Alternative
Peec AI Alternative
Profound Alternative
Otterly.AI Alternative
Rankscale Alternative
SOCi Alternative
Use Cases
Sales Teams
Lead Generation
Retention & Upsell
Agentic Workflows
Website Builders
Resellers
Industries
Marketing Agencies
Hosting & Registrars
Directories
Media
Telecoms
SaaS
Resources
Blog
Product Updates
Success Stories
AI Visibility Report
AEO Guidebook
Free AI Audit
FiveInsites Newsletter
Company
About Insites
Pricing
Careers
Contact
Insites is a registered trademark of Insites Technologies Ltd. Insites is registered in England and Wales. Company no: 13479874. VAT: GB 384 0954 73, EU 372 0467 67.
Privacy Terms Cookie Policy Legal