{"id":75994,"date":"2025-09-02T14:41:18","date_gmt":"2025-09-02T18:41:18","guid":{"rendered":"https:\/\/syndigo.com\/?page_id=75994"},"modified":"2026-02-12T14:42:38","modified_gmt":"2026-02-12T19:42:38","slug":"responsible-disclosure-notice","status":"publish","type":"page","link":"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/","title":{"rendered":"Responsible Disclosure Notice"},"content":{"rendered":"\n<section class=\"wp-block-group hero-legal is-layout-constrained wp-block-group-is-layout-constrained\"><div class=\"wp-block-group__inner-container\">\n<h1 class=\"wp-block-heading has-text-align-center\" id=\"h-responsible-disclosure-notice\">Responsible Disclosure Notice<\/h1>\n<\/div><\/section>\n\n\n\n<div class=\"wp-block-group legal-box is-layout-constrained wp-block-group-is-layout-constrained\"><div class=\"wp-block-group__inner-container\">\n<h2 class=\"wp-block-heading has-medium-font-size\" id=\"h-this-page-is-for-security-researchers-interested-in-reporting-application-security-vulnerabilities\">This page is for security researchers interested in reporting application security vulnerabilities.<\/h2>\n\n\n\n<p>If you have reported an issue determined to be within scope, is determined to be a valid security issue, and you have followed program guidelines, Syndigo will recognize your finding and you will be allowed to disclose the vulnerability after a fix has been issued. Please refer all questions to the provided Bugcrowd form below. Although Syndigo is unable to offer compensation for reported findings (confirmed or not), responsibly disclosing these vulnerabilities are appreciated and are utilized in advancing the security field.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-typical-vulnerabilities-requiring-responsible-disclosure\">Typical vulnerabilities requiring responsible disclosure:<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OWASP Top 10 vulnerability categories<\/li>\n\n\n\n<li>Other vulnerabilities with demonstrated impact<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-program-guidelines\"><strong>Program Guidelines:<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>All forms of social engineering are strictly prohibited (phishing, vishing, smishing).<\/li>\n\n\n\n<li>Performing vulnerability scans against Syndigo and its assets is strictly prohibited.<\/li>\n\n\n\n<li>If user\/client\/vendor information is found in any form, do not verify them. Please inform us and we will validate them.<\/li>\n\n\n\n<li>Adhere to all legal terms and conditions outlined at Syndigo.com.<\/li>\n\n\n\n<li>Work directly with Syndigo on vulnerability submissions.<\/li>\n\n\n\n<li>Provide detailed description of a proof of concept to detail reproduction of vulnerabilities.<\/li>\n\n\n\n<li>Do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems.<\/li>\n\n\n\n<li>Do not engage in social engineering or phishing of customers or employees.<\/li>\n\n\n\n<li>Do not request compensation for time and materials or vulnerabilities discovered.<\/li>\n<\/ul>\n\n\n\n<p>When submitting your vulnerability report, we request that the following are not submitted to us. We have numerous programs and tools internally that allow us to look for these categories of vulnerabilities and have likely already detected them, if present:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Out-of-date software<\/li>\n\n\n\n<li>Theoretical vulnerabilities<\/li>\n\n\n\n<li>Informational disclosure of non-sensitive data<\/li>\n\n\n\n<li>Low impact session management issues<\/li>\n\n\n\n<li>Self XSS (user defined payload)<\/li>\n\n\n\n<li>Any attack requiring physical access to Syndigo offices, devices, servers, data centers, personnel, or any physical location.<\/li>\n\n\n\n<li>User enumeration through brute forcing techniques or enumeration which requires message confirmations generated by Syndigo services, (i.e. using the forgotten password option and receiving a &#8220;user does not exist message&#8221;).<\/li>\n\n\n\n<li>CSRF issues that don&#8217;t impact the integrity of an account.<\/li>\n\n\n\n<li>Non-sensitive files and directories disclosure (e.g. README.TXT, CHANGES.TXT, robots.txt, .gitignore, WSDL, pprof, etc.)<\/li>\n\n\n\n<li>Login or Forgot Password page brute force, account lockout not enforced, or insufficient password strength requirements<\/li>\n\n\n\n<li>Descriptive error messages (e.g. stack traces, application or server errors, path disclosure)<\/li>\n\n\n\n<li>Fingerprinting\/banner disclosure on common\/public services<\/li>\n\n\n\n<li>Clickjacking or any attack that requires clickjacking as a prerequisite.<\/li>\n\n\n\n<li>TLS\/SSL Issues, including BEAST BREACH, insecure renegotiation, bad cipher suite, expired certificates, etc.<\/li>\n\n\n\n<li>Email spoofing (including SPF, DKIM, DMARC, <em>From:<\/em> spoofing, and visually similar, and related issues)<\/li>\n\n\n\n<li>WAF bypass<\/li>\n\n\n\n<li>Open redirects<\/li>\n\n\n\n<li>Lack of security speed bump page<\/li>\n\n\n\n<li>Internal IP address disclosure<\/li>\n\n\n\n<li>Self XSS<\/li>\n\n\n\n<li>Text injection<\/li>\n\n\n\n<li>Mass submissions\/account creation<\/li>\n\n\n\n<li>Lack of Secure and HTTP <\/li>\n\n\n\n<li>Only cookie flags<\/li>\n\n\n\n<li>HTTPS mixed content scripts<\/li>\n\n\n\n<li>Missing security headers<\/li>\n\n\n\n<li>All forms of Dos \/ DDoS<\/li>\n\n\n\n<li>Spelling and\/or grammar mistakes<\/li>\n<\/ul>\n\n\n\n<script async src=\"https:\/\/bugcrowd.com\/6562d068-8351-4c64-a6cc-7eaed1fa65fe\/external\/script\"\n data-bugcrowd-program=\"https:\/\/bugcrowd.com\/6562d068-8351-4c64-a6cc-7eaed1fa65fe\/external\/report\"><\/script>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","_page_status":"none","program_name":"","program_hidden_field_name":"","footnotes":""},"class_list":["post-75994","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.8 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Responsible Disclosure Notice | Syndigo Security<\/title>\n<meta name=\"description\" content=\"Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Responsible Disclosure Notice | Syndigo Security\" \/>\n<meta property=\"og:description\" content=\"Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/\" \/>\n<meta property=\"og:site_name\" content=\"Syndigo\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/syndigoLLC\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-12T19:42:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/syndigo.com\/wp-content\/uploads\/2024\/01\/Syndigo.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1292\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@syndigoLLC\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/\",\"url\":\"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/\",\"name\":\"Responsible Disclosure Notice | Syndigo Security\",\"isPartOf\":{\"@id\":\"https:\/\/syndigo.com\/de\/#website\"},\"datePublished\":\"2025-09-02T18:41:18+00:00\",\"dateModified\":\"2026-02-12T19:42:38+00:00\",\"description\":\"Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.\",\"breadcrumb\":{\"@id\":\"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/syndigo.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Responsible Disclosure Notice\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/syndigo.com\/de\/#website\",\"url\":\"https:\/\/syndigo.com\/de\/\",\"name\":\"Syndigo\",\"description\":\"Data Unlocked. Potential Unleashed.\",\"publisher\":{\"@id\":\"https:\/\/syndigo.com\/de\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/syndigo.com\/de\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/syndigo.com\/de\/#organization\",\"name\":\"Syndigo\",\"url\":\"https:\/\/syndigo.com\/de\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/syndigo.com\/de\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/syndigo.com\/wp-content\/uploads\/2024\/01\/Syndigo.png\",\"contentUrl\":\"https:\/\/syndigo.com\/wp-content\/uploads\/2024\/01\/Syndigo.png\",\"width\":696,\"height\":696,\"caption\":\"Syndigo\"},\"image\":{\"@id\":\"https:\/\/syndigo.com\/de\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/syndigoLLC\",\"https:\/\/x.com\/syndigoLLC\",\"https:\/\/www.linkedin.com\/company\/syndigo\",\"https:\/\/www.youtube.com\/channel\/UC4W-3BtMfXVAwReREonADRg\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Responsible Disclosure Notice | Syndigo Security","description":"Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Responsible Disclosure Notice","og_description":"Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.","og_url":"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/","og_site_name":"Syndigo","article_publisher":"https:\/\/www.facebook.com\/syndigoLLC","article_modified_time":"2026-02-12T19:42:38+00:00","og_image":[{"width":1292,"height":720,"url":"https:\/\/syndigo.com\/wp-content\/uploads\/2024\/01\/Syndigo.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_site":"@syndigoLLC","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/","url":"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/","name":"Responsible Disclosure Notice | Syndigo Security","isPartOf":{"@id":"https:\/\/syndigo.com\/de\/#website"},"datePublished":"2025-09-02T18:41:18+00:00","dateModified":"2026-02-12T19:42:38+00:00","description":"Report security vulnerabilities responsibly. Learn Syndigo\u2019s disclosure guidelines, scope, and reporting process for researchers.","breadcrumb":{"@id":"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/syndigo.com\/de\/responsible-disclosure-notice\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/syndigo.com\/"},{"@type":"ListItem","position":2,"name":"Responsible Disclosure Notice"}]},{"@type":"WebSite","@id":"https:\/\/syndigo.com\/de\/#website","url":"https:\/\/syndigo.com\/de\/","name":"Syndigo","description":"Data Unlocked. Potential Unleashed.","publisher":{"@id":"https:\/\/syndigo.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/syndigo.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/syndigo.com\/de\/#organization","name":"Syndigo","url":"https:\/\/syndigo.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/syndigo.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/syndigo.com\/wp-content\/uploads\/2024\/01\/Syndigo.png","contentUrl":"https:\/\/syndigo.com\/wp-content\/uploads\/2024\/01\/Syndigo.png","width":696,"height":696,"caption":"Syndigo"},"image":{"@id":"https:\/\/syndigo.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/syndigoLLC","https:\/\/x.com\/syndigoLLC","https:\/\/www.linkedin.com\/company\/syndigo","https:\/\/www.youtube.com\/channel\/UC4W-3BtMfXVAwReREonADRg"]}]}},"coauthors":[],"author_meta":{"author_link":"https:\/\/syndigo.com\/de\/author\/vignesh\/","display_name":"Vignesh Sivaraj"},"relative_dates":{"created":"Posted 7 months ago","modified":"Updated 2 months ago"},"absolute_dates":{"created":"Posted on September 2, 2025","modified":"Updated on February 12, 2026"},"absolute_dates_time":{"created":"Posted on September 2, 2025 2:41 pm","modified":"Updated on February 12, 2026 2:42 pm"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/pages\/75994","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/comments?post=75994"}],"version-history":[{"count":9,"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/pages\/75994\/revisions"}],"predecessor-version":[{"id":84560,"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/pages\/75994\/revisions\/84560"}],"wp:attachment":[{"href":"https:\/\/syndigo.com\/de\/wp-json\/wp\/v2\/media?parent=75994"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}