Vulnerability Disclosure Policy
Effective Date: July 25, 2026
Introduction
Vimes, Inc. is committed to protecting the information entrusted to us including Criminal Justice Information (CJI) handled on behalf of our customers and to keeping our systems secure. We recognize the important role independent security researchers play in that effort, and we want to make it easy for you to tell us what you've found.
This policy describes what systems and types of research are covered under this policy; how to send us a vulnerability report; and how long we ask you to wait before publicly disclosing a vulnerability.
We encourage you to contact us to report potential vulnerabilities in our systems.
Authorization
If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and Vimes will not recommend or pursue legal action related to your research, including under our Terms of Service or Acceptable Use Policy.
If a third party initiates legal action against you for activities conducted consistent with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Guidelines
Under this policy, “research” means activities in which you:
Notify us as soon as possible after you discover a real or potential security issue;
Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or corruption of data during your research;
Only use exploits to the extent necessary to confirm a vulnerability's presence; do not use an exploit to exfiltrate data, establish command-line access or persistence, or use the exploit to pivot to other systems;
Provide us a reasonable amount of time (see Section 7, Disclosure) to resolve the issue before you disclose it publicly; and
Do not submit a high volume of low-quality reports.
Once you've established that a vulnerability exists, or encounter any sensitive data — including CJI, personally identifiable information, financial information, or proprietary information or trade secrets of any party — you must stop your test, notify us immediately, and must not disclose this data to anyone else.
Scope
This policy applies to the following systems and services:
Product / property In-scope domains / assets
Vimes.com
Vimesapp.com
Vulnerabilities found in systems or services that are not owned by Vimes fall outside the scope of this policy. Please report those to the responsible party. Non-production, staging, or development environments are also out of scope unless explicitly listed above.
Rules of Engagement
Security researchers must not:
Test any system or account other than your own, or without the explicit permission of the account holder;
Disclose vulnerability information except as set forth in the “Reporting a Vulnerability” and “Disclosure” sections below;
Conduct physical testing (e.g. office access, tailgating) or social engineering (e.g. phishing, vishing, pretexting) of Vimes personnel, contractors, or customers;
Conduct denial-of-service (DoS/DDoS) testing or any testing that degrades service availability or performance;
Introduce malicious software into Vimes or customer systems;
Test third-party applications, websites, or services that integrate with or are linked from Vimes systems; or
Delete, alter, share, retain, or destroy Vimes or customer data, including CJI, or intentionally view or access any such data beyond the minimum necessary to demonstrate a vulnerability.
Security researchers may:
View or store nonpublic data only to the extent necessary to document the presence of a vulnerability, and only for as long as necessary to report it.
Security researchers must:
Cease testing and notify us immediately upon discovery of a vulnerability;
Cease testing and notify us immediately upon discovery of exposed nonpublic data (including CJI); and.
Purge any stored nonpublic data obtained through your research upon reporting the vulnerability to us.
Reporting a Vulnerability
Reports may be submitted to: admin@vimes.io. Reports may be submitted anonymously.
Vulnerability types we want to hear about
We are especially interested in reports involving vulnerabilities with a genuine, demonstrable security impact, including but not limited to:
Remote code execution, command injection, or server-side request forgery (SSRF)
SQL injection or other injection vulnerabilities
Authentication or authorization bypass, including privilege escalation and insecure direct object references (IDOR)
Exposure of sensitive data, credentials, or CJI, including through misconfigured storage, logging, or access controls
Cross-site scripting (XSS) or cross-site request forgery (CSRF) with a demonstrated impact
Business logic flaws that allow unauthorized access to functionality or data
Exploitable vulnerabilities in supply-chain or third-party dependency components as deployed in our systems
Vulnerability types we generally don't need reported
The following are typically not actionable on their own, absent a demonstrated exploitable impact, and reporting them is not required under this policy:
Missing security headers or cookie flags without a demonstrated exploit
Self-XSS, clickjacking on pages with no sensitive actions, or issues requiring an unlikely degree of user interaction
Software version disclosure or banner grabbing
Rate-limiting or brute-force reports without a demonstrated account-takeover path
Best-practice recommendations that do not correspond to an exploitable vulnerability
What to include in your report
To help us triage and prioritize your submission, please include:
A statement that your research was conducted consistent with this policy
A description of the vulnerability and its potential impact
The affected system, URL, endpoint, or component
Step-by-step reproduction instructions, including any tools, payloads, or scripts used
Proof-of-concept code, screenshots, or a short screen recording where applicable (use redacted or synthetic data--do not include real customer data or CJI)
We accept reports about vulnerabilities for defensive purposes only. We do not use reports to build offensive capability. Where a vulnerability affects a shared or widely used product or component, we may share your report--without your name unless you tell us otherwise--with the affected vendor or with the Cybersecurity and Infrastructure Security Agency (CISA) for coordinated disclosure.
Disclosure
Vimes asks that you give us 60 days from the date of your report to investigate and remediate a confirmed vulnerability before you disclose it publicly or to any third party. Disclosing a vulnerability before a fix is available tends to increase risk rather than reduce it, so we ask that you coordinate the timing of any public disclosure with us in advance.
We do not require an indefinite embargo on public disclosure as a condition of authorizing your research. If we have not resolved a confirmed issue or substantively responded within the agreed timeframe, you are free to disclose it publicly, and we ask only that you continue to avoid revealing any sensitive data encountered during testing.
Questions
Questions about this policy can be directed to admin@vimes.io.
Content last reviewed August 10, 2026