Tecton Vulnerability Disclosure Program | Tecton

Tecton

Tecton Vulnerability Disclosure Program

Tecton Vulnerability Disclosure Program

Overview:

Our bug bounty program allows ethical hackers and security researchers to earn rewards for discovering and reporting security vulnerabilities in our software.

Scope:

Our bug bounty program is limited to our production services and includes public-facing web applications, and APIs developed by us. Unfortunately, we cannot accept reports for third-party administered applications or websites at this time.  *Note that our Marketing site ‘Tecton.ai’ is also explicitly not included in this program as it is administered by a 3rd party.  The following systems are considered in-scope:

explore.tecton.ai

Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us at security@tecton.ai before starting your research.

Though we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We will increase the scope of this policy over time.

Guidelines:

Under this policy, “research” means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
  • Do not submit a high volume of low-quality reports.
  • Once you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Test methods:

The following test methods are not authorized:

  1. Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data
  2. Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing

Rewards:

We offer rewards from a range of $100 to $500 for qualifying bugs.  Existing and known bugs are not paid.  The amount awarded will depend on the severity and impact of the vulnerability.  Severity of vulnerabilities is determined using CVSS 4.0.

Reporting Process:

To report a bug, please email security@tecton.ai. Submissions should include at minimum a summary and steps to reproduce the issue.  We aim to respond within 3 business days and resolve valid reports within 14 days.

Authorization

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and Tecton will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

Let's keep in touch

Stay up to date with the latest product updates, upcoming events, and industry news with Tecton’s newsletter.

© Tecton, Inc. All rights reserved. Various trademarks held by their respective owners.

Book a Demo

Unfortunately, Tecton does not currently support these clouds. We’ll make sure to let you know when this changes!

However, we are currently looking to interview members of the machine learning community to learn more about current trends.

If you’d like to participate, please book a 30-min slot with us here and we’ll send you a $50 amazon gift card in appreciation for your time after the interview.

CTA link

or

CTA button

Contact Sales

Interested in trying Tecton? Leave us your information below and we’ll be in touch.​

Unfortunately, Tecton does not currently support these clouds. We’ll make sure to let you know when this changes!

However, we are currently looking to interview members of the machine learning community to learn more about current trends.

If you’d like to participate, please book a 30-min slot with us here and we’ll send you a $50 amazon gift card in appreciation for your time after the interview.

CTA link

or

CTA button

Request a free trial

Interested in trying Tecton? Leave us your information below and we’ll be in touch.​

Unfortunately, Tecton does not currently support these clouds. We’ll make sure to let you know when this changes!

However, we are currently looking to interview members of the machine learning community to learn more about current trends.

If you’d like to participate, please book a 30-min slot with us here and we’ll send you a $50 amazon gift card in appreciation for your time after the interview.

CTA link

or

CTA button