Responsible Vulnerability Disclosure
This page is for independent security researchers who want to report or investigate vulnerabilities on the SyncSign platform.
The information on this page is intended only for security researchers who are interested in reporting security vulnerabilities on SyncSign. If you are a SyncSign customer and have questions, contact our customer service team at help[at]sync-sign.com.
If you believe that you have discovered a security vulnerability on SyncSign, we strongly encourage you to inform us and to not disclose the vulnerability publicly.
Reporting a potential security vulnerability:
Privately send details of the vulnerability to SyncSign team by sending an email to dev[at]sync-sign.com
Please provide full details of the vulnerability, including:
Type of issue (buffer overflow, SQL injection, cross-site scripting, etc.)
Product and version that contains the bug, or URL
Service packs, security updates, or other updates for the product you have installed
Any special configuration required to reproduce the issue
Step-by-step instructions to reproduce the issue on a fresh install
Proof-of-concept or exploit code
Impact of the issue, including how an attacker could exploit the issue
SyncSign follows Coordinated Vulnerability Disclosure (CVD) and, to protect the ecosystem, we request that those reporting to us do the same.
We appreciate your assistance, and we review all reports and do our best to address the issues within the specified time frame.