Responsible Disclosure Policy
At Aspen Blue Capital LLC ("Aspen") we value the work of the security community. This Policy explains how to report a vulnerability in our systems and what we commit to in return for those who do so in good faith.
If you find a vulnerability, we want to hear about it. Report it to business@aspenbluecapital.com with the subject line "Security report". Please do not publish it before we have fixed it.
1. How to report
Send your report to business@aspenbluecapital.com, including as far as possible:
- A description of the vulnerability and the impact it could have.
- Detailed steps to reproduce it (proof of concept).
- The URL, endpoint or component affected.
- Any relevant logs, screenshots or evidence.
- A way to contact you for follow-up.
2. Our commitments
- Acknowledgement of receipt within five (5) business days of your report.
- Initial assessment and severity classification within ten (10) business days.
- Keeping you informed of progress until the fix is in place.
- Publicly acknowledging your contribution if you wish.
- Taking no legal action against anyone acting in accordance with this Policy (see clause 4).
Aspen does not currently run a paid rewards programme (bug bounty). Reports are handled and credited, but we make no commitment to payment.
3. Rules for good-faith reporting
For your research to be covered by this Policy, you must:
- Act in good faith, without intent to cause harm or obtain undue benefit.
- Not access, modify, extract or retain third-party data. If you come across personal data, stop immediately and tell us.
- Use only accounts you own or accounts created for the test.
- Not degrade the service: no denial-of-service attacks, no load testing, no spam.
- Not use social engineering against our staff, customers or users, and no physical attacks.
- Not disclose the vulnerability publicly or to third parties until we have fixed it and agreed the timing with you.
- Comply with applicable law.
4. Safe harbor
If you research and report in compliance with this Policy, Aspen will consider your activity authorised, will not initiate or support legal action against you for that research, and will cooperate to clarify your good faith if a third party were to initiate such action. This safe harbor does not cover conduct that goes beyond this Policy, nor does it release you from liability towards third parties whose systems or data you may have affected.
5. Scope
In scope:
- The site aspenbluecapital.com and its subdomains.
- The AIBI platform and its APIs.
- Vulnerabilities allowing unauthorised access to accounts or data, privilege escalation, remote code execution, injection, authentication bypass, or bypass of the separation between accounts (multi-tenant).
Out of scope:
- Third-party systems (for example, our sub-processors): report those directly to them.
- Automated scanner findings with no demonstrable impact.
- Missing security headers, email configuration best practices (SPF/DMARC) or version-related issues with no demonstrated exploitation.
- Attacks requiring physical access, a compromised device or social engineering.
- Denial of service and resource exhaustion.
- Incorrect AI model output (hallucinations or inappropriate answers): these are not security vulnerabilities. Report them as product issues under the Responsible AI Policy. What IS in scope is anything that allows access to another account's data or bypasses security controls.
6. Contact
business@aspenbluecapital.com — subject line "Security report".