Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Trust Center / Report a Vulnerability

Security researchers and members of the public can provide an important outside perspective. If you believe you have found a vulnerability in a Gov2Biz-owned system or service, report it promptly so our team can assess the issue and take appropriate action.

01

Help us investigate effectively

A useful report allows our team to understand what is affected, reproduce the behavior, and evaluate the potential impact without repeating risky testing.

Send your report to infosec.alert@gov2biz.com and include as much of the following as possible:

The affected product, service, hostname, page, or endpoint
A clear description of the suspected vulnerability
The steps needed to reproduce it
The potential security or privacy impact
Relevant screenshots, request and response details, or proof-of-concept material
Your name and preferred contact information
Whether you would like to be acknowledged for the report

Do not send personal information, credentials, customer data, or other sensitive material unless it is necessary to explain the issue. If sensitive material is required, ask us to coordinate an appropriate secure-transfer method.

02

Research without creating additional harm

We ask researchers to act in good faith and use restraint. Testing should confirm the suspected issue, not expand its impact.

When investigating a potential vulnerability:

Avoid privacy violations, data loss, service disruption, and degradation of user experience.
Test only to the extent needed to confirm and document the issue.
Do not access, change, download, retain, or disclose another party's data.
Do not perform denial-of-service testing, destructive testing, social engineering, phishing, physical attacks, or attacks against Gov2Biz personnel or providers.
Do not introduce malware or use a suspected vulnerability to move into other systems.
Stop testing and contact Gov2Biz immediately if you encounter sensitive data or gain unintended access.
Give Gov2Biz a reasonable opportunity to investigate and address the issue before public disclosure.
Comply with applicable law.
03

What happens after you report

Gov2Biz will review reports received through the designated channel. We may contact you to clarify the behavior, request additional technical detail, or coordinate next steps.

We prioritize reports using factors such as reproducibility, affected scope, likelihood, potential impact, and risk to customers or users. Resolution time varies with the complexity, severity, and dependencies of the issue.

Gov2Biz does not operate a public bug-bounty program and does not promise payment or compensation unless agreed in writing before the submission.

04

What is in scope

This policy applies to publicly accessible systems and services owned and operated by Gov2Biz.

Customer-controlled environments, customer data, third-party services, and systems not operated by Gov2Biz are outside scope unless Gov2Biz confirms otherwise in writing. If you are uncertain whether a target is in scope, contact infosec.alert@gov2biz.com before testing.

05

Use the right channel for the issue

This process is for suspected security vulnerabilities. Customer support, privacy requests, fraud, payment disputes, and other operational matters should be directed to the appropriate Gov2Biz support or contact channel.

A responsible report helps protect public services

Send a detailed report to infosec.alert@gov2biz.com . We appreciate the time and care required to disclose a potential issue responsibly.