Vulnerability Disclosure Policy
Vital Brands Inc.
At Vital Brands Inc., we are committed to safeguarding our systems, protecting sensitive information, and ensuring the security of our customers, partners, and employees. We take cybersecurity seriously and recognize the importance of privacy, security, and responsible community collaboration.
We are dedicated to addressing and reporting security issues through a coordinated and constructive approach that prioritizes the protection of technology users and the confidentiality of all information entrusted to us.
Reporting Security Issues
If you believe you have discovered a vulnerability in any Vital Brands Inc. asset, system, or service—or if you have a security incident to report—please contact us immediately by emailing:
security@vitalbrandsinc.com
(Please update this with your actual security contact email.)
When submitting a report, you agree to the following:
- Respect Privacy: If you access personal data, account information, or any sensitive content, you must stop testing immediately and contact us. You must not save, store, share, or transmit such information.
- Act in Good Faith: Submit your findings responsibly and without attaching conditions or demands.
- Work Collaboratively: Promptly report your findings and stop after identifying the first vulnerability unless given explicit permission to continue. Allow reasonable time for investigation and remediation before making any public disclosure.
Prohibited Actions
When conducting security research related to Vital Brands Inc., you must not:
- Exfiltrate, extract, or misuse any data. Use only the minimum proof of concept necessary to demonstrate the issue.
- Exploit any vulnerability to disable or bypass security controls.
- Engage in social engineering, including phishing or impersonation.
- Use automated scanners, brute-force tools, or any intrusive technologies without prior written consent.
Next Steps After Reporting
Upon receiving your report:
- Vital Brands Inc. will request that all communications regarding the vulnerability remain confidential.
- We will promptly investigate and verify the reported issue.
- We will address the vulnerability through appropriate means, including patches, updates, or guidance on mitigations.
- We will make reasonable efforts to keep you informed of the progress and resolution.
Our Commitment to Security Researchers
We appreciate and value the contributions of ethical security researchers who help us strengthen the security of our products and services. By responsibly disclosing vulnerabilities, you play an important role in helping Vital Brands Inc. protect our community, systems, and information.
Thank you for your cooperation and for contributing to a safer digital environment.