Vantris Solutions (“Vantris”) values the work of security researchers who help us keep vantrissolutions.com (the “Site”) and our systems secure. This policy explains how to report a potential vulnerability and what to expect from us.
1. Purpose
If you believe you have found a security vulnerability affecting Vantris systems, we want to hear from you. This policy sets out how to report it responsibly and the protection we offer researchers who do.
2. Scope
| In scope | Out of scope |
|---|---|
| vantrissolutions.com and its subdomains | Third-party services we link to but do not operate (e.g., Acumatica’s own platform) |
| Systems and infrastructure Vantris owns and operates | Social engineering, phishing, or physical attacks against Vantris staff or facilities |
| Denial-of-service testing |
If you are unsure whether a system is in scope, contact us before testing.
3. Reporting a Vulnerability
Email contact@vantrissolutions.com with:
- A clear description of the vulnerability and its potential impact
- Steps to reproduce it, including any proof-of-concept
- The URL, IP address, or system affected
- Your contact information for follow-up
Do not include sensitive data you were able to access in your report; describe what you found instead.
4. Our Commitment
If you make a good-faith effort to comply with this policy when researching and reporting a vulnerability, we will:
- Acknowledge your report within 3 business days
- Provide a status update within 10 business days
- Not pursue legal action against you for your research, provided you acted in accordance with this policy
- Credit you (with your permission) once the issue is resolved, if you would like recognition
We ask that you give us reasonable time to investigate and remediate before disclosing the issue publicly. Provided your research and disclosure comply fully with this policy, Vantris will not initiate or support a civil claim against you, and will not refer your conduct to law enforcement for a potential offence under the Criminal Code of Canada, including section 342.1 (unauthorized use of a computer). This policy is governed by the laws of Canada.
5. Guidelines for Researchers
When testing, you agree to:
- Avoid privacy violations, data destruction, or service interruption
- Only interact with accounts and data you own or have explicit permission to test
- Stop testing and notify us immediately if you access data that is not yours
- Give us a reasonable window to remediate before any public disclosure
- Comply with applicable law throughout your research
6. Out of Scope
The following are not eligible under this policy:
- Reports generated by automated scanners without a demonstrated, exploitable impact
- Missing security headers or cookie flags with no proven exploit
- Issues requiring physical access to a device
- Findings on out-of-scope or third-party systems (see Section 2)
- Social engineering or phishing of Vantris staff
7. Contact
Reports and questions about this policy:
Vantris Solutions
Email: contact@vantrissolutions.com