Vulnerability Disclosure Policy
How to report a security vulnerability to MuchSkills
1. Our commitment
MuchSkills welcomes reports from security researchers and customers who find a potential vulnerability in our service. We will acknowledge your report, investigate it, keep you informed, and fix confirmed issues as quickly as we reasonably can. We will not take legal action against anyone who reports a vulnerability in good faith and in line with this policy. Testing carried out in accordance with this policy is authorised by MuchSkills for the purposes of its Acceptable Use Policy and of applicable computer-misuse law, and MuchSkills will not treat it as a breach of any agreement with you. That authorisation applies only to testing against your own account and data. It does not extend to load, denial-of-service, high-volume automated or social-engineering testing, does not authorise access to or degradation of service for any other customer, and does not waive any obligation you owe under an agreement between MuchSkills and your employer.
2. How to report
Email security@muchskills.com with enough detail to reproduce the issue: what you found, where, and the steps to reproduce it. Please report promptly and give us a reasonable time to fix the issue before disclosing it to anyone else.
3. Please do, and please do not
- Please do: test only against your own account or data; report as soon as you find something; and give us reasonable time to respond.
- Please do not: access, modify or delete other people's data; run denial-of-service or high-volume automated tests; use social engineering or physical attacks; or publicly disclose the issue before we have fixed it and agreed timing with you.
4. What to expect
We aim to acknowledge a report within a few business days, confirm whether we can reproduce it, and agree a remediation timeline with you for confirmed issues. We are grateful for responsible reports and will credit you where you would like us to and where it is appropriate. MuchSkills does not currently operate a paid bug-bounty programme.