Empathy First Media Security Vulnerability Disclosure Policy

Last Updated: January 7, 2024

Introduction

At Empathy First Media, we prioritize the security of our systems and data. We recognize the valuable role that security researchers and our user community play in keeping our systems secure. This policy provides guidelines for submitting security vulnerabilities to us and outlines our commitment to working with security researchers.

Scope

This policy applies to any digital assets owned, operated, or maintained by Empathy First Media.

How to Report a Security Vulnerability

If you believe you have found a security vulnerability in one of our systems, please send us a detailed report to [email protected]. Your report should include:

  • A clear description of the vulnerability and potential impact.
  • Detailed steps to reproduce the vulnerability (Proof of Concept scripts or screenshots can be helpful).
  • Any relevant URLs or affected systems.
  • Your contact information for follow-up.

For secure communication, our PGP key is available at PGP Key Link.

What to Expect After Reporting a Vulnerability

  1. Acknowledgment: We aim to acknowledge receipt of your report within 48 hours.
  2. Assessment: We will work to validate and assess the vulnerability.
  3. Communication: We will keep you informed of our progress.
  4. Remediation: Once assessed, we will work swiftly to address the issue.
  5. Disclosure: We are committed to responsible disclosure and will coordinate with you regarding public disclosure of the vulnerability.

Safe Harbor

When conducting vulnerability research according to this policy, we consider this research to be:

  • Authorized concerning any anti-hacking laws.
  • Exempt from DMCA violations related to circumventing technological measures.
  • Exempt from violations of the Computer Fraud and Abuse Act.

We will not pursue legal action against individuals who report vulnerabilities, provided they adhere to this policy. We ask that you:

  • Do not access or modify data without permission.
  • Avoid degradation of user experience, disruption to production systems, and destruction of data during security testing.
  • Refrain from disclosing vulnerability details to the public before a mutually agreed-upon timeframe expires.

Acknowledgments

Security researchers who follow this policy and responsibly disclose vulnerabilities will be recognized on our Acknowledgments page: Hall of Fame Link.

Contact Us

For any questions regarding this policy, please contact [email protected].

Daniel Lynch, EIT
Daniel Lynch, EIT
https://empathyfirstmedia.com/team/daniel-lynch-eit/
Daniel Lynch is an experienced digital marketing consultant with technical expertise in various industries, primarily integrative medicine, IV therapy, and healthcare. Formerly a structural engineer, Daniel is an expert in digital marketing, building his businesses Medical Bill Gurus, Empathy First Media, Biologix Mobile Wellness, and IV League from the ground up with SEO, Public Relations, Website Development, and Paid Search (PPC/SEM).
Preloader image
Skip to content