Accessibility Statement

Responsible Disclosure Policy

At Tractive, we consider the security of our systems, apps, and devices a top priority. No matter how much effort we put into security, vulnerabilities can still exist and we appreciate the community's help in finding them so we can address them as quickly as possible. This policy explains what is in scope, how to report an issue, and what you can expect from us in return.

How to report a vulnerability

All reports must be submitted through our Bug Bounty program hosted by HackerOne at this link. This is the only channel we monitor for vulnerability reports; submissions sent by other means may not be tracked or eligible for a reward.

When you submit, please include:

  • A clear description of the vulnerability and its potential impact.
  • Reproduction steps — step-by-step instructions to reproduce the issue, including the URLs, endpoints, and any specific parameters involved.
  • Evidence — screenshots or screen recordings that illustrate the problem.
  • Affected system details — the specific subdomain, service, or endpoint concerned.
  • Expected vs. actual behavior — what you expected to happen versus what actually occurred.

Usually the URL or IP address of the affected system plus a clear description is enough; complex vulnerabilities may need further explanation. Ideally, a reported vulnerability should be reproducible without physical access to a target's device.

Scope

We are interested in reports for the primary platforms, apps, devices and services that Tractive directly manages and controls.

Out of scope. Vulnerabilities in third-party services or subdomains that are not directly controlled by Tractive are out of scope. This includes, but is not limited to:

  • Subdomains such as help.tractive.com (operated by Zendesk).
  • Third-party services, including those provided by our partners or vendors.
  • Missing or misconfigured response headers (e.g., Content-Security-Policy, Feature-Policy, Referrer-Policy, X-XSS-Protection, X-Permitted-Cross-Domain-Policies) without a demonstrable security impact or working exploit on our platform.
  • Findings produced solely by automated tools or scans without a demonstrated, exploitable impact.

Reports about out-of-scope domains will not be eligible for a reward and should be directed to the appropriate third-party provider.

Rules of engagement

If you believe you have discovered a security vulnerability in a Tractive service, please do the following:

  • Submit your findings by using our bug bounty program hosted by HackerOne.
  • Do not take advantage of the vulnerability or problem you have discovered. In particular, you must not access, download, exfiltrate, modify or access data beyond what is strictly necessary to demonstrate the vulnerability.
  • You must not access or attempt to access accounts belonging to other users under any circumstances. Testing must be performed exclusively on accounts that you own.
  • If the vulnerability involves personal data, you must not access or process such data, except to the extent strictly necessary to report the issue. You must not store, copy, or share any such data. This is critically important, so let us emphasize it: do not interact with the data in question more than is necessary to notify us.
  • Do not reveal the problem to others until it has been resolved.
  • Do not use attacks on physical security, social engineering, distributed denial of service (or any attack using large volumes of requests), spam, or applications of third parties.
  • Please provide sufficient information to reproduce the problem so we can resolve it as quickly as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.

Ideally, a reported vulnerability will be achievable without physical access to a target’s device.

In addition, while we welcome disclosure reports from automated tools/scans, we cannot offer a reward.

What we promise

  • We thank you for your help in making Tractive more secure.
  • We will respond to an accepted report within 5 business days with our evaluation of the report.
  • As long as you act in good faith and comply with this policy and applicable laws, we will not take any legal action against you in connection with your report. We will handle your personal information in accordance with applicable data protection laws and our Privacy Policy and will not publicly disclose your identity without your permission, unless required by law.
  • We will keep you informed of the progress towards resolving the problem.
  • In the public information concerning the problem reported, we will give your name as the discoverer of the problem (unless you desire otherwise).

Rewards

As a token of our gratitude, we may offer a reward for every report of a security problem that was not already known to us and that potentially has customer impact on one of our in-scope platforms.

  • Rewards are granted entirely at our discretion. The amount is based on the severity of the vulnerability and the quality of the report.
  • Rewards are provided only for verified, in-scope vulnerabilities that have not been previously reported or already known to us.
  • Reports concerning third-party systems, previously identified issues, or findings generated solely by automated scans are not eligible for a reward.
  • A reward may be reduced or declined if there is evidence of abuse.
  • If someone violates these guidelines — repeatedly or continuously — we reserve the right to disqualify them from receiving rewards and, if necessary, to block further participation in the program.

Questions

If you have any questions about this Responsible Disclosure Policy, contact us at security@tractive.com.