Vulnerability Reporting Policy
At Attitude community, trust is our #1 value and we take the protection of our customers’ data very
The Attitude community security team acknowledges the valuable role that independent security
researchers play in internet security. As a result, we encourage responsible reporting of
any vulnerabilities that may be found in our site or applications. Attitude community is committed to
working with security researchers to verify and address any potential vulnerabilities that
are reported to us.
Please review these terms before you test and/or report a vulnerability. Attitude community
pledges not to initiate legal action against researchers for penetrating or attempting to
penetrate our systems as long as they adhere to this policy.
LEGAL INDEX PAGE
Testing for security vulnerabilities:
Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing
against such instances. Always use test or demo accounts when testing our online
Reporting a potential security vulnerability:
Provide full details of the suspected vulnerability so the Salesforce security team may
validate and reproduce the issue.
Attitude community does not permit the following types of security research:
While we encourage you to discover and report to us any vulnerabilities you find in a
responsible manner, the following conduct is expressly prohibited:
Performing actions that may negatively affect Attitude community or its users (e.g. Spam, Brute
Force, Denial of Service…) Accessing, or attempting to access, data or information that
does not belong to you, Destroying or corrupting, or attempting to destroy or corrupt, data
or information that does not belong to you, Conducting any kind of physical or electronic
attack on Attitude community personnel, property or data centers Social engineering any Attitude community service desk, employee or contractor, Conduct vulnerability testing of participating
services using anything other than test accounts (e.g. Developer or Trial Edition instances)
Violating any laws or breaching any agreements in order to discover vulnerabilities.
The Attitude community security team commitment:
We ask that you do not share or publicize an unresolved vulnerability with/to third parties.
If you responsibly submit a vulnerability report, the Attitude community security team and
associated development organizations will use reasonable efforts to:
Respond in a timely manner, acknowledging receipt of your vulnerability report
Provide an estimated time frame for addressing the vulnerability report
Notify you when the vulnerability has been fixed
We are happy to thank every individual researcher who submits a vulnerability report
helping us improve our overall security posture at Attitude community.