{"id":14012,"date":"2026-09-01T15:34:14","date_gmt":"2026-09-01T19:34:14","guid":{"rendered":"https:\/\/advisoryloom.com\/almain\/?page_id=14012"},"modified":"2026-09-01T15:34:19","modified_gmt":"2026-09-01T19:34:19","slug":"vulnerability-disclosure-policy","status":"publish","type":"page","link":"https:\/\/advisoryloom.com\/almain\/vulnerability-disclosure-policy\/","title":{"rendered":"Vulnerability Disclosure Policy"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Effective date: September 1, 2026<br>Operator: Draper Security LLC. AdvisoryLoom is a brand and product operated by Draper Security LLC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A bounded, good-faith reporting framework for security researchers that excludes disruptive testing and third-party systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Purpose<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Draper Security LLC welcomes responsible reports that help protect AdvisoryLoom and its users. This policy describes the systems and methods authorized for good-faith security research. It does not authorize testing outside the stated scope or conduct prohibited below.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. In-scope systems<\/h2>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>advisoryloom.com web properties and subdomains that display AdvisoryLoom content and are directly operated by Draper Security LLC; and<\/li>\n\n\n\n<li>AdvisoryLoom account and application functions directly controlled by Draper Security LLC.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If ownership is unclear, ask before testing. A third-party logo, integration, embedded frame, link, API, or hosted checkout does not make that system in scope.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. Out-of-scope systems and findings<\/h2>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>hosting-provider, DNS-provider, registrar, CDN, email-provider, or other infrastructure not directly controlled by Draper Security LLC;<\/li>\n\n\n\n<li>Stripe, Cloudflare, OpenAI, WordPress.org, publishers, vendors, government services, CVE services, GitHub, and all other third-party systems;<\/li>\n\n\n\n<li>physical facilities, employees, contractors, customers, and personal devices;<\/li>\n\n\n\n<li>missing best-practice headers or low-impact configuration observations without a demonstrated security consequence;<\/li>\n\n\n\n<li>self-XSS, clickjacking on pages without sensitive actions, username enumeration without impact, rate-limit observations without a reproducible risk, and reports produced only by an automated scanner without validation; and<\/li>\n\n\n\n<li>issues in obsolete browsers, unsupported software, or a dependency for which no practical AdvisoryLoom impact is shown.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">4. Authorized research<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Research is authorized only when you:<\/p>\n\n\n\n<ol start=\"9\" class=\"wp-block-list\">\n<li>use accounts and data you own or have explicit permission to use;<\/li>\n\n\n\n<li>make a good-faith effort to avoid privacy violations, degradation, disruption, excessive traffic, and damage;<\/li>\n\n\n\n<li>limit requests to the minimum necessary to confirm a finding and keep automated traffic at no more than two requests per second unless we give written permission;<\/li>\n\n\n\n<li>stop immediately if you encounter personal, confidential, authentication, payment, or other non-public data that is not yours;<\/li>\n\n\n\n<li>do not retain, copy, alter, transmit, or disclose data beyond the minimum evidence needed for the report;<\/li>\n\n\n\n<li>report promptly and allow a reasonable time for investigation and remediation before public disclosure; and<\/li>\n\n\n\n<li>comply with this policy and applicable law.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">5. Prohibited conduct<\/h2>\n\n\n\n<ol start=\"16\" class=\"wp-block-list\">\n<li>denial-of-service, stress, load, capacity, resource-exhaustion, or high-volume scanning;<\/li>\n\n\n\n<li>social engineering, phishing, pretexting, bribery, threats, extortion, or contacting users or staff for credentials;<\/li>\n\n\n\n<li>password spraying, credential stuffing, brute force, stolen credentials, session theft, or multi-factor fatigue;<\/li>\n\n\n\n<li>malware, ransomware, destructive payloads, persistence, backdoors, cryptomining, or command-and-control activity;<\/li>\n\n\n\n<li>accessing, downloading, changing, deleting, or exfiltrating another person&#8217;s data;<\/li>\n\n\n\n<li>testing payment methods, initiating fraudulent transactions, or testing Stripe or other third parties;<\/li>\n\n\n\n<li>bypassing physical controls or attacking networks, devices, or accounts not expressly in scope;<\/li>\n\n\n\n<li>supply-chain attacks, dependency confusion, typosquatting, or publishing malicious packages;<\/li>\n\n\n\n<li>public disclosure before coordinated disclosure is agreed or a reasonable remediation period has passed; and<\/li>\n\n\n\n<li>any conduct that creates material risk to users, Draper Security LLC, or third parties.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">6. How to report<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Email support@advisoryloom.com with the subject &#8220;Security Vulnerability Report.&#8221; Encrypt sensitive reports when practical and do not use public issue trackers. Include:<\/p>\n\n\n\n<ol start=\"26\" class=\"wp-block-list\">\n<li>the affected URL, feature, version, and environment;<\/li>\n\n\n\n<li>a clear description of the issue and realistic impact;<\/li>\n\n\n\n<li>minimal reproducible steps or proof of concept;<\/li>\n\n\n\n<li>dates and times, request and response details with secrets redacted, and supporting screenshots if useful;<\/li>\n\n\n\n<li>whether any data was encountered and confirmation that testing stopped; and<\/li>\n\n\n\n<li>your preferred name, contact method, and disclosure expectations.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">7. What to expect<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We aim to acknowledge a complete report within five business days and provide an initial status within 15 business days. Resolution time depends on severity, complexity, provider dependencies, and verification needs. We may request additional information, merge duplicate reports, or determine that a report is not a vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Draper Security LLC does not currently operate a bug-bounty program and does not promise payment, gifts, public credit, CVE assignment, or employment. We may offer recognition only with the researcher&#8217;s permission.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">8. Safe harbor<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When research is conducted in good faith, remains within the authorization and limits of this policy, and is promptly reported, Draper Security LLC will not initiate or support legal action based solely on that compliant research. If we believe compliant research was conducted accidentally outside a technical control, we will first attempt to clarify and resolve the matter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This safe harbor does not cover violations of law unrelated to good-faith research, threats or extortion, privacy violations, data misuse, prohibited conduct, third-party systems, or activity after we ask you to stop. Draper Security LLC cannot authorize research on behalf of third parties and cannot bind prosecutors, regulators, service providers, or other persons.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">9. Changes and contact<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We may update this policy as systems and risks change. Questions about scope should be sent to support@advisoryloom.com before testing. Mail may be sent to Draper Security LLC, 2746 Kirby Road, Draper, VA 24324.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Effective date: September 1, 2026Operator: Draper Security LLC. AdvisoryLoom is a brand and product operated by Draper Security<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-14012","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/pages\/14012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/comments?post=14012"}],"version-history":[{"count":1,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/pages\/14012\/revisions"}],"predecessor-version":[{"id":14013,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/pages\/14012\/revisions\/14013"}],"wp:attachment":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/media?parent=14012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}