Security
Reporting a vulnerability
We take the security of our platform and our customers' data seriously. If you believe you've found a security vulnerability in a Polar Analytics product or service, we'd like to hear from you and will work with you to resolve it quickly.
Email security@polaranalytics.co with:
- the affected system, URL, or endpoint;
- a description of the issue and its potential impact;
- steps to reproduce (proof-of-concept, screenshots, or a short video).
Our commitments
We assess severity using CVSS v3.1 and aim to meet the following timelines:
- Critical: Acknowledgement within 1 business day, Immediate interim mitigation, Remediation within 30 days.
- High: Acknowledgement within 2 business days, Remediation within 30 days.
- Medium: Acknowledgement within 5 business days, Remediation within 60 days.
- Low: Acknowledgement within 10 business days, Remediation within 90 days.
We'll keep you informed of our progress and let you know when the issue is resolved.
Safe harbor
We will not pursue or support legal action against researchers who act in good faith and who:
- make a genuine effort to avoid privacy violations, data destruction, and interruption or degradation of our services;
- only access or modify data to the minimum extent needed to demonstrate the issue, and do not access, store, or share other users' data;
- give us a reasonable time to remediate before disclosing publicly.
Scope
In scope: production Polar Analytics applications, APIs, and supporting infrastructure (e.g. polaranalytics.com, app.polaranalytics.com, and our production API domains).
Out of scope: findings that require physical access or a compromised device; social engineering of staff or customers; volumetric denial-of-service; and vulnerabilities in third-party services we don't control.
