Security researchers and members of the public can provide an important outside perspective. If you believe you have found a vulnerability in a Gov2Biz-owned system or service, report it promptly so our team can assess the issue and take appropriate action.
A useful report allows our team to understand what is affected, reproduce the behavior, and evaluate the potential impact without repeating risky testing.
Send your report to infosec.alert@gov2biz.com and include as much of the following as possible:
Do not send personal information, credentials, customer data, or other sensitive material unless it is necessary to explain the issue. If sensitive material is required, ask us to coordinate an appropriate secure-transfer method.
We ask researchers to act in good faith and use restraint. Testing should confirm the suspected issue, not expand its impact.
When investigating a potential vulnerability:
Gov2Biz will review reports received through the designated channel. We may contact you to clarify the behavior, request additional technical detail, or coordinate next steps.
We prioritize reports using factors such as reproducibility, affected scope, likelihood, potential impact, and risk to customers or users. Resolution time varies with the complexity, severity, and dependencies of the issue.
Gov2Biz does not operate a public bug-bounty program and does not promise payment or compensation unless agreed in writing before the submission.
This policy applies to publicly accessible systems and services owned and operated by Gov2Biz.
Customer-controlled environments, customer data, third-party services, and systems not operated by Gov2Biz are outside scope unless Gov2Biz confirms otherwise in writing. If you are uncertain whether a target is in scope, contact infosec.alert@gov2biz.com before testing.
This process is for suspected security vulnerabilities. Customer support, privacy requests, fraud, payment disputes, and other operational matters should be directed to the appropriate Gov2Biz support or contact channel.
Send a detailed report to infosec.alert@gov2biz.com . We appreciate the time and care required to disclose a potential issue responsibly.