# Vulnerability Disclosure Policy

| Version | Effective | Approved | Last reviewed | Owner |
|---|---|---|---|---|
| 1.4 | October 2, 2026 | October 2, 2026 | October 2, 2026 | Brian Johnson, President |

!!!info About This Document
This policy explains how security researchers and members of the public can report a vulnerability in a system 7 Minute Security LLC operates, and what we commit to in return. It is the policy referenced by our security.txt.
!!!

## 1. Our Commitment

7 Minute Security LLC ("7MinSec") is a cybersecurity firm. We find vulnerabilities in other people's systems for a living, so we understand the value of a good-faith report, and we want reporting one to us to be simple and safe. If you believe you have found a security vulnerability in a system we operate, we want to hear from you.

## 2. Scope

### 2.1 In Scope

- 7minsec.com, www.7minsec.com, and every subdomain of 7minsec.com, for issues we are in a position to fix: our DNS records, our configuration of a site or service, our accounts, and the content we publish. Examples: a subdomain pointing somewhere we no longer control, an outdated or misconfigured plugin on our website, information we should not have published.
- Any other internet-facing system that 7MinSec operates directly.

### 2.2 Out of Scope

- **Systems belonging to 7MinSec clients.** We test client systems only under written authorization. Do not test them on our behalf.
- Vulnerabilities in the platforms our sites and services run on (our web host, our static-site host, or the third-party products behind subdomains such as share.7minsec.com and training.7minsec.com), where the fix belongs to the vendor. If you are not sure whose bug it is, tell us anyway; we will route it or point you to the vendor's disclosure program.
- Third-party services we use but do not operate: our email and productivity platforms, our helpdesk platform, or our podcast and newsletter hosts. Please report those to the vendor.
- Denial-of-service testing, resource exhaustion, or anything that degrades availability
- Social engineering of 7MinSec personnel, clients, or partners
- Physical attacks against 7MinSec property or people
- Output from automated scanners without a demonstrated, exploitable impact
- Missing security headers, email authentication configuration (SPF/DKIM/DMARC), or software version disclosure without a working exploit

If you are unsure whether something is in scope, ask first at [security@7minsec.com](mailto:security@7minsec.com).

## 3. How to Report

Email **[security@7minsec.com](mailto:security@7minsec.com)**. Please include:

- A description of the vulnerability and the system affected
- Steps to reproduce, with a proof of concept where practical
- The potential impact as you understand it
- How you would like to be credited, if at all

If your report contains sensitive detail you would prefer not to send in plain email, say so in your first message and we will arrange an encrypted channel.

## 4. What to Expect From Us

- We will acknowledge your report within **3 business days**
- We will give you an initial assessment and an expected timeline within **10 business days**
- We will keep you informed as we work, and fix confirmed issues as quickly as their severity warrants
- If you would like it, we will credit you in our [Hall of Thanks](https://kb.7minsec.com/trust/hall-of-thanks) once the issue is resolved

## 5. What We Ask of You

- Act in good faith to avoid privacy violations, destruction of data, and disruption of service
- Access only the minimum data needed to demonstrate the issue. Do not retain, copy, or share it
- Stop immediately and tell us if you encounter client data, credentials, or personal information
- Do not use a vulnerability beyond what is needed to prove it exists. No pivoting, persistence, or lateral movement
- Give us a reasonable time to fix the issue before disclosing it publicly. We ask for **90 days** from your report, and we will coordinate the disclosure with you

## 6. Safe Harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue or support legal action against you for research conducted in accordance with this policy, and we will work with you to understand and resolve the issue quickly. If a third party initiates legal action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorized.

This policy does not authorize activity against systems we do not own or operate.

## 7. Rewards

7MinSec does not operate a paid bug bounty program. We are a small firm and would rather say so plainly than be vague about it. What we can offer is a prompt, respectful response, a fix, and a place in our Hall of Thanks if you want it.

## 8. security.txt

Machine-readable contact details for this policy are published in accordance with [RFC 9116](https://www.rfc-editor.org/rfc/rfc9116) at [7minsec.com/.well-known/security.txt](https://7minsec.com/.well-known/security.txt).

## 9. Policy Review

This policy is reviewed annually or following any significant change to the systems we operate. The current version is published in the [7MinSec Trust Center](https://kb.7minsec.com/trust).

## Change Log

This log records all changes made to this policy over time.

| Version | Date | Author | Description of Change |
|---|---|---|---|
| 1.0 | September 1, 2026 | Brian Johnson | Initial release. |
| 1.1 | September 23, 2026 | Brian Johnson | No substantive change. Version aligned with the rest of the policy suite following the September 2026 review. |
| 1.1.1 | September 24, 2026 | Brian Johnson | Editorial pass ahead of publication: em dashes removed throughout. No commitment changed. |
| 1.2 | September 28, 2026 | Brian Johnson | Reviewed by an independent assessor against the CIS Controls with no changes required. Version aligned with the rest of the policy suite. |
| 1.3 | October 2, 2026 | Brian Johnson | Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. No change to this policy. Version aligned with the rest of the suite. |
| 1.4 | October 2, 2026 | Brian Johnson | No change to this policy. Version aligned with the rest of the suite. |

!!!info Document Feedback
To suggest changes to this policy or report an issue, contact: [security@7minsec.com](mailto:security@7minsec.com)
!!!

*Last reviewed: October 2, 2026*
