Security

Vulnerability Disclosure Policy

Responsible security research and coordinated disclosure for YourCreditPal.

1. Introduction and Purpose

YourCreditPal Company Limited operates a loan referral and lead generation platform that collects, processes, and transfers sensitive consumer financial data to Lending Partners. The security of these systems is fundamental to our obligations to consumers and regulators. This Vulnerability Disclosure Policy (VDP) establishes a clear, legally protected channel for security researchers to report vulnerabilities to us responsibly. It is aligned to CISA's Coordinated Vulnerability Disclosure guidance and ISO/IEC 29147.

2. Scope

2.1 In Scope

  • yourcreditpal.com (main website, all pages, subdomains, and interactive forms);
  • Lead submission and consumer loan inquiry forms;
  • Consumer account portal and authenticated areas;
  • YourCreditPal API endpoints used for lead transmission and Lending Partner integrations;
  • YourCreditPal email infrastructure;
  • YourCreditPal mobile website and associated subdomains.

2.2 Out of Scope

The following are not authorized under this Policy and do not benefit from the safe harbor in Section 3:

  • Third-party Lending Partner or service provider systems;
  • Denial of service (DoS / DDoS) or any testing that impairs system availability;
  • Social engineering, phishing, or physical security testing;
  • Automated high-volume scanning that degrades system performance;
  • Any system, domain, or IP address not listed above.

3. Safe Harbor

If you make a good-faith effort to comply with this Policy, YourCreditPal will: consider your research authorized under the CFAA and other applicable computer crime laws; not initiate or recommend civil or criminal legal action against you; and work with you cooperatively to understand and resolve the issue.

The safe harbor is conditional on full compliance with this Policy. It does not apply to deliberate access to or retention of consumer data, attacks on out-of-scope systems, disclosure to third parties before remediation, or conduct that violates applicable law for reasons unrelated to the vulnerability discovery. YourCreditPal will advocate on your behalf to any authority where we believe you acted in compliance with this Policy. This Policy is governed by the laws of the State of Delaware.

4. Researcher Conduct

4.1 Required

  • Notify YourCreditPal immediately upon discovering a real or potential vulnerability;
  • Stop testing immediately upon encountering consumer data; after confirming a vulnerability, limit further testing to what is necessary to document the vulnerability's scope and impact;
  • Use exploits only to the minimum extent necessary to confirm the vulnerability exists;
  • Use only synthetic, clearly fictitious test data (never real consumer personal or financial data);
  • Notify YourCreditPal of any test accounts created so we can remove them;
  • Give YourCreditPal the coordinated disclosure period (Section 7) before any public disclosure;
  • Submit reports in English with sufficient detail to reproduce the issue.

4.2 Prohibited

The following voids the safe harbor in Section 3:

  • Accessing, downloading, copying, retaining, or transmitting consumer personal or financial data;
  • DoS / DDoS attacks or testing that impairs availability of any YourCreditPal system;
  • Social engineering, phishing, vishing, or physical security testing;
  • Testing against third-party Lending Partner or service provider systems;
  • Disclosing vulnerability details or consumer data to any third party before YourCreditPal authorizes disclosure;
  • Demanding payment or threatening disclosure as a condition of reporting (extortion will be reported to law enforcement). For the avoidance of doubt, routine inquiries about whether recognition is available do not constitute demands;
  • Introducing malware, backdoors, or any persistent access into YourCreditPal systems.

5. Severity Classification and Response SLAs

YourCreditPal uses a four-tier severity system aligned to CVSS v3.1. Severity determines our internal response SLA:

SeveritySLAExample VulnerabilitiesCVSS Range & Commitment
CRITICAL

Ack: 24 h

Triage: 48 h

Fix: 14 days

Unauthenticated RCE; SQL injection on consumer DB; auth bypass; mass data exfiltration; consent record tampering.CVSS 9.0-10.0. Immediate escalation to CISO.
HIGH

Ack: 24 h

Triage: 72 h

Fix: 30 days

Authenticated RCE; IDOR exposing consumer records; stored XSS in lead forms; sensitive data in API responses.CVSS 7.0-8.9. Fortnightly status updates.
MEDIUM

Ack: 3 days

Triage: 5 days

Fix: 60 days

Reflected XSS; misconfigured SPF/DKIM/DMARC; weak session management; sensitive data in error messages.CVSS 4.0-6.9. Monthly status updates.
LOW

Ack: 5 days

Triage: 10 days

Fix: 90 days

Missing security headers; verbose server banners; clickjacking on low-sensitivity pages; best-practice deviations.CVSS 0.0-3.9. Best-efforts remediation.

6. How to Submit a Vulnerability Report

Send your report through our secure submission form or by email to contact@yourcreditpal.com with the subject line: VULNERABILITY DISCOVERED and a brief description.

Please include in your report:

  • A clear summary of the vulnerability and its potential impact;
  • Date and time of discovery; affected URLs, endpoints, or IP addresses;
  • Step-by-step reproduction instructions with proof-of-concept (no real consumer data);
  • Your severity assessment (Critical / High / Medium / Low) and CVSS score if known;
  • CVE ID if assigned; known mitigation or remediation if available;
  • Screenshots, HTTP logs, or code snippets supporting the finding;
  • Your name / handle, email, phone, and whether you intend to publish the finding.

If you encounter real consumer personal or financial data during research: stop immediately, do not copy or retain it, describe only what you observed (not actual values), confirm deletion in your report, and notify us at once.

7. Coordinated Disclosure Timeline

The standard coordinated disclosure period is 90 calendar days from our acknowledgement of your report. During this period, neither party will disclose the vulnerability publicly. We may request a reasonable extension for complex remediations and will communicate any extension with a clear explanation and revised timeline.

Where we fail to remediate within the agreed timeline without satisfactory explanation, you may give 14 days' written notice of intent to publish. We request that any planned publication be shared with us at least 7 days in advance and that it does not include real consumer data or unexploited technical specifics that could enable further harm.

8. What You Can Expect from YourCreditPal

  • Acknowledgement within the SLA for your reported severity (Section 5);
  • A human response from our Security Team, not an automated reply;
  • Our severity assessment and explanation of any difference from yours;
  • Estimated remediation timeline after triage, with updates if it changes;
  • Notification when the vulnerability has been fixed and verified;
  • Public credit on our Security Acknowledgements page (optional; you may choose to remain anonymous);
  • Good-faith interpretation of ambiguous conduct where you have acted transparently.

We will not share your identity with third parties without consent (except where required by law), use your report against you in any proceeding where you have complied with this Policy, or ignore your report without explanation. Where multiple researchers independently report the same vulnerability, credit will be given to the first reporter whose submission contains sufficient detail to reproduce the issue.

We do not currently operate a formal bug bounty programme. For validated Critical or High severity findings, we may, at our sole discretion, offer financial recognition on a case-by-case basis.

9. Policy Governance

This Policy is owned by the YourCreditPal Security Team, and reviewed annually or following any significant security incident, change in applicable law, or material change to YourCreditPal's technology infrastructure.

10. Vulnerability Reporting Form

When submitting a report via our Vulnerability Disclosure Form or by email to contact@yourcreditpal.com, please include the following information:

  • Summary of Vulnerability: One or two sentence description of the issue.
  • Date and Time Discovered: Date, time, and time zone.
  • How the Vulnerability Was Discovered: Method, tools, and steps that led to discovery.
  • Affected Systems / URLs / Endpoints / IPs: List all affected systems and URLs.
  • Reproduction Steps: Step-by-step instructions; include HTTP requests/payloads where relevant.
  • Impact Assessment: What data or actions are exposed? Who is affected and how severely?
  • Severity and CVSS Score: Critical/High/Medium/Low; CVSS v3.1 score and vector if known.
  • CVE ID (if assigned): CVE identifier, or state if you intend to request one.
  • Supporting Evidence: Attach screenshots, HTTP logs, or PoC code. Do not include real consumer data.
  • Known Mitigation or Remediation: Describe any fix or workaround you are aware of.
  • Public Disclosure Intentions: Do you intend to publish? If so, on what timeline and format?
  • Consumer Data Contact: Did you encounter real consumer data? If yes, describe what you observed and confirm deletion.
  • Researcher Details: Name/handle, organization, email, phone number.