Swimlane is committed to the security of our products and services. We welcome reports from security researchers who identify vulnerabilities in our systems. This policy outlines how to report a vulnerability, what to expect from us, and the terms under which you may conduct security research.
How to Report
Send your report to [email protected]. Anonymous reports are accepted.
In Scope
- Swimlane Turbine (shared cloud, dedicated cloud, and on-premises deployments)
- Swimlane 10.x (shared cloud, dedicated cloud, and on-premises deployments)
- Swimlane APIs associated with the above products
- swimlane.com and all public-facing Swimlane subdomains
Out of Scope
- Third-party services and tools that Swimlane uses but does not own or operate
- Employee personal accounts and devices
- Physical security testing
- Social engineering of Swimlane employees
- Vulnerabilities discovered through automated scanning tools without prior written approval
- Any system not listed above
Prohibited Activities
- Introduce malware or malicious code into any Swimlane system
- Copy, modify, or delete data that does not belong to you
- Make unauthorized changes to Swimlane systems or services
- Repeatedly access systems beyond what is necessary to confirm the vulnerability
- Conduct brute-force attacks
- Conduct denial-of-service attacks
- Social engineer Swimlane employees or contractors
What to Include in Your Report
- A description of the vulnerability and where it was found
- Steps to reproduce or proof of concept
- Your assessment of the potential impact
Our Commitments
- We will acknowledge your report within 2 business days
- We will complete an initial triage and provide an update within 5 business days
- We will keep you informed as we work to resolve the issue
- We will notify you when the vulnerability has been resolved
Coordinated Disclosure
Please do not publicly disclose the details of a vulnerability until we have had the opportunity to investigate and remediate it. Our default coordinated disclosure window is 90 days from the date we confirm receipt of a valid report. We will work with you on the timing of any disclosure.
Safe Harbor
If you make a good-faith effort to comply with this policy during your security research, Swimlane will consider your research to be authorized, work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, Swimlane will make this authorization known.
