Vulnerability Disclosure Policy
Neocom Software Corporation is committed to maintaining the security of TRBOnet products, services, and websites.
We welcome reports from security researchers, customers, and the broader security community. If you believe you have identified a security vulnerability, please report it responsibly using the process described below.
Scope
This policy applies to:
- Supported versions of TRBOnet products
- TRBOnet websites
- Supported digital services owned and operated by Neocom Software Corporation
If you believe a vulnerability affects a third-party product or service, please report it directly to the appropriate vendor.
Reporting a Vulnerability
Please report security vulnerabilities by email:
To help us investigate your report, please include:
- Product name and version (if applicable)
- Affected URL (if applicable)
- Description of the vulnerability
- Steps to reproduce the issue
- Expected and actual behavior
- Potential impact
- Proof of concept, screenshots, or logs (if available)
- Your contact information
The more information you provide, the faster we can investigate and validate your report.
What You Can Expect From Us
When you report a security issue, we will:
- Acknowledge receipt of your report.
- Review and validate reported vulnerabilities.
- Contact you if additional information is required.
- Assess confirmed vulnerabilities based on their potential impact and prioritize them according to our vulnerability management process.
- Work to resolve confirmed security issues.
- Keep you informed about the progress of your report where appropriate.
Our target is to acknowledge new reports within 5 business days.
We will maintain the confidentiality of your report and your contact information, except where disclosure is required by law or necessary to coordinate remediation with affected parties.
Security Updates
Where appropriate, confirmed vulnerabilities are addressed through software updates, patches, configuration guidance, or other mitigation measures. We encourage customers to keep their TRBOnet installations up to date by using supported product versions.
Responsible Disclosure
When conducting security research, we ask that you:
- Act in good faith.
- Report vulnerabilities as soon as reasonably possible.
- Avoid violating the privacy of other users.
- Avoid disrupting our systems or services.
- Access only data that belongs to you or for which you have explicit authorization.
- Stop testing immediately if you unintentionally access sensitive information and report the issue to us.
- Allow us reasonable time to investigate and resolve the issue before publicly disclosing it.
Out of Scope
The following are generally considered out of scope:
- Third-party systems or services not owned or operated by Neocom Software Corporation
- Spam or phishing reports
- Social engineering attacks
- Physical security issues
- Denial-of-service attacks
- Reports generated solely by automated scanners without demonstrating a security impact
- Issues affecting unsupported or outdated software versions
- Reports without sufficient information to reproduce the issue
Safe Harbor
If you conduct security research in good faith, comply with this policy, avoid privacy violations, service disruption, or data destruction, and promptly report discovered vulnerabilities, Neocom Software Corporation will not pursue legal action against you for your research.
This Safe Harbor applies only to legal claims under the control of Neocom Software Corporation and does not apply to third parties.
Contact
Security Team
security@trbonet.com
Last updated: July 30, 2026