Vulnerability Disclosure Policy
Version 1.0 · Effective 3 September 2026
On this page
1. Introduction 2. Guidelines for Researchers 3. Authorisation and Safe Harbour 4. Scope 5. Types of Testing Not Authorised 6. Non-Qualifying Findings 7. Reporting a Vulnerability 8. Information We Would Like in Your Report 9. Our Commitment and Response Times 10. Coordinated Disclosure 11. Recognition 12. Contact1. Introduction
Xpert Group FZE-LLC, the company behind SignSyncer, is committed to preserving the security of the data entrusted to us and to preventing the unauthorised disclosure of information. Security researchers play an important part in that.
This policy gives security researchers clear instructions for conducting vulnerability discovery activity against our systems, and explains how to report the vulnerabilities they find. It sets out which systems and which types of activity are covered, how to send us a report, and how long we ask you to wait before disclosing a finding publicly.
We welcome reports from everyone, including our own customers, partners, and members of the public. You do not need to be a professional researcher to report something to us.
2. Guidelines for Researchers
We ask that you:
- Notify us as soon as possible after you discover a real or potential security issue.
- Give us a reasonable amount of time to resolve the issue before you disclose it publicly.
- Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems, and the destruction or manipulation of data.
- Only use an exploit to the extent necessary to confirm that a vulnerability is present. Do not use an exploit to compromise or exfiltrate data, to establish command-line access or persistence, or to pivot to other systems.
- Stop testing immediately once you have established that a vulnerability exists, or as soon as you encounter any sensitive data — including personal data, credentials, financial information, or the proprietary information or trade secrets of any party. Notify us at once and keep that data strictly confidential.
- Delete any sensitive data you obtained in the course of your research as soon as you have reported it to us, and confirm that you have done so.
- Use only test accounts that you own, or accounts you have explicit written permission to test. Do not access, modify, or delete data belonging to another user.
- Do not submit a high volume of low-quality reports, and do not submit the raw output of an automated scanner without validating the findings yourself.
3. Authorisation and Safe Harbour
Security research carried out in conformity with this policy is deemed authorised. If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorised, we will work with you to understand and resolve the issue quickly, and Xpert Group FZE-LLC will not recommend or pursue legal action in connection with your research.
If a third party initiates legal action against you in connection with activities that you conducted in good faith under this policy, we will make it known that your actions were carried out with our authorisation.
This authorisation does not extend to activity that intentionally harms our users, degrades our Service, or breaches applicable law. You remain responsible for complying with the laws that apply to you.
4. Scope
This policy applies only to the following systems and services:
| Asset | Status |
|---|---|
https://signsyncer.com — marketing website and public tools | In scope |
https://app.signsyncer.com — SignSyncer web application portal | In scope |
| Public APIs served from the domains above and used by the web application | In scope |
Web application only. SignSyncer is currently delivered as a web application. We do not operate mobile applications, browser extensions, or desktop clients at this time, and no such platform is in scope for this policy. If we release one, we will update this policy and add it to the table above.
Any service not explicitly listed above — including related services, staging or development environments, and internal corporate systems — is out of scope and is not authorised for testing.
Vulnerabilities discovered in third-party solutions that SignSyncer interacts with (for example Google Workspace, Microsoft 365, payment processors, or hosting providers) are not covered by this policy and should be reported directly to that vendor in accordance with their own disclosure policy. If you are unsure whether a system or endpoint is in scope, email us at support@signsyncer.com before you begin.
5. Types of Testing Not Authorised
The following test types are not authorised under this policy:
- Network denial of service (DoS or DDoS) testing, volumetric testing, or any activity that degrades availability for other users
- Physical testing, such as attempting office access, testing doors, or tailgating
- Social engineering of our staff, customers, or suppliers, including phishing, vishing, and smishing
- Any other non-technical vulnerability testing
- Automated scanning that generates excessive traffic or floods forms, sign-up flows, or email delivery
- Testing against accounts, mailboxes, or directories that you do not own or have permission to test
- Attempting to access, modify, or destroy production data belonging to our customers
6. Non-Qualifying Findings
The following are generally not considered actionable vulnerabilities by themselves. We will still read your report, but we may close it without action unless you can demonstrate a realistic security impact:
- Missing security headers or cookie flags with no demonstrated exploit
- Missing or misconfigured SPF, DKIM, or DMARC records without a working spoofing proof of concept
- Clickjacking on pages with no sensitive state-changing action
- Self-XSS, or issues requiring the victim to paste code into their own browser console
- Reports of outdated software versions without a demonstrated exploitable path
- Rate limiting on non-authentication endpoints, unless abuse impact is demonstrated
- Username or email enumeration on public sign-up flows
- Vulnerabilities that require a rooted, jailbroken, physically compromised, or malware-infected device
- Issues affecting only unsupported or end-of-life browsers
- Unvalidated output from automated scanning tools
7. Reporting a Vulnerability
To report a security flaw, send an email to support@signsyncer.com with the subject line beginning "Security Report".
We will acknowledge receipt of your report by the next business day and will keep you updated on our progress. Reports may be submitted anonymously. If you choose to report anonymously, we will still investigate and remediate, but we will not be able to send you updates.
Please do not disclose the issue publicly, to other users, or on social media before we have had the opportunity to address it. Please do not include live customer data in your report; redact it and describe what you found instead.
8. Information We Would Like in Your Report
To help us process and react to your report quickly, please include as much of the following as you can:
- A description of the vulnerability and the vulnerability class (for example, stored XSS, IDOR, SSRF)
- The place of discovery — the exact URL, endpoint, parameter, or feature affected
- The potential impact, and what an attacker could realistically achieve
- Clear step-by-step instructions required to reproduce the issue, including any scripts, requests, or payloads used
- Screenshots or a short screen recording, where they help
- The date and time of your testing, and the source IP address you tested from, so we can correlate our logs
- Any suggested remediation, if you have one
- Whether you intend to disclose the issue publicly, and on what timeline
Where possible, please submit your report in English.
9. Our Commitment and Response Times
If you choose to share your contact details, we commit to communicating with you transparently and promptly. We welcome discussion of your findings and are happy to engage in a technical dialogue.
| Stage | Target |
|---|---|
| Acknowledgement of receipt | Next business day, and no later than 3 business days |
| Initial triage and severity assessment | Within 5 business days |
| Status update cadence | At least every 10 business days until closure |
| Remediation — Critical severity | Target 7 calendar days |
| Remediation — High severity | Target 30 calendar days |
| Remediation — Medium severity | Target 90 calendar days |
| Remediation — Low severity | Next scheduled release cycle |
We assess severity using the Common Vulnerability Scoring System (CVSS), adjusted for the real-world exploitability and data exposure risk in our environment. We will keep you informed on confirmation of the vulnerability and on remediation to the best of our ability.
10. Coordinated Disclosure
We ask that you give us 90 calendar days from the date of your report before disclosing a vulnerability publicly. If we fix the issue sooner, we are happy to agree an earlier disclosure date with you. If remediation is complex and needs longer, we will explain why and agree a revised timeline with you rather than let the deadline pass in silence.
Where a vulnerability affects our customers' data, we will follow our Incident Response Policy and notify affected customers and, where required, the relevant supervisory authorities.
11. Recognition
SignSyncer does not currently operate a paid bug bounty programme. We do maintain a security acknowledgements list, and with your permission we will credit you there by name or handle for valid, previously unreported findings. If you would prefer not to be named, tell us and we will keep your report confidential.
12. Contact
Xpert Group FZE-LLC
Business Center, SPC Free Zone, Al Zahia
Sharjah, United Arab Emirates
Phone: +971 50 433 4829
Security reports: support@signsyncer.com
This policy is reviewed at least annually and whenever our platform scope changes.