Vulnerability Disclosure Policy
Responsible Security Research and Vulnerability Reporting
Effective Date: January 1, 2026
Sunol Tech LLC is committed to maintaining the security of our systems, services, websites, and customer-facing platforms. We appreciate the efforts of security researchers and members of the security community who responsibly identify and report potential vulnerabilities.
1. Purpose
This Vulnerability Disclosure Policy provides a process for reporting security vulnerabilities discovered in systems owned or operated by Sunol Tech LLC and outlines our commitment to investigating and addressing valid reports.
2. Scope
This policy applies to:
- Sunol Tech LLC public websites
- Customer portals and web applications
- Public APIs and cloud-hosted services
- Internet-facing systems owned by Sunol Tech LLC
- Authorized digital assets controlled by Sunol Tech LLC
This policy does not apply to third-party platforms, vendors, manufacturers, or systems not owned or controlled by Sunol Tech LLC.
3. Responsible Disclosure Guidelines
Security researchers acting in good faith should:
- Report vulnerabilities promptly after discovery.
- Avoid actions that could harm customers, employees, or systems.
- Avoid accessing, modifying, or deleting data that does not belong to them.
- Minimize disruption to business operations.
- Provide sufficient information to reproduce and validate findings.
- Allow reasonable time for remediation before public disclosure.
4. Prohibited Activities
The following activities are not authorized under this policy:
- Accessing customer accounts without permission.
- Downloading, altering, or destroying data.
- Social engineering, phishing, or impersonation attacks.
- Physical security testing.
- Denial-of-service (DoS) or distributed denial-of-service (DDoS) testing.
- Ransomware deployment or malware testing.
- Password attacks, credential stuffing, or brute-force attacks.
- Any activity that violates applicable laws or regulations.
5. How to Submit a Vulnerability Report
Please include as much detail as possible:
- Description of the vulnerability.
- Affected system, application, or URL.
- Steps required to reproduce the issue.
- Potential security impact.
- Proof-of-concept screenshots or logs when available.
- Your contact information for follow-up questions.
Sunol Tech LLC Security Team
Email: [email protected]
Phone: (XXX) XXX-XXXX
Subject Line: Vulnerability Disclosure Report
6. What You Can Expect From Us
When a valid report is submitted, Sunol Tech LLC will generally:
- Acknowledge receipt of the report.
- Review and validate reported findings.
- Communicate with the researcher when additional information is required.
- Work to remediate confirmed vulnerabilities.
- Notify the reporter when remediation efforts are complete when practical.
7. Safe Harbor
Sunol Tech LLC supports responsible security research conducted in good faith and in accordance with this policy.
We will not initiate legal action against researchers who:
- Follow this policy.
- Act in good faith.
- Avoid privacy violations and service disruption.
- Promptly report discovered vulnerabilities.
Activities outside the scope of this policy may result in investigation and legal action.
8. No Compensation Program
Unless specifically stated otherwise, Sunol Tech LLC does not operate a bug bounty program and does not guarantee financial compensation for vulnerability reports.
9. Confidentiality
We request that researchers maintain confidentiality regarding reported vulnerabilities until remediation has been completed or public disclosure has been approved by Sunol Tech LLC.
10. Third-Party Products
Many products sold, distributed, integrated, or supported by Sunol Tech LLC are manufactured by third parties. Vulnerabilities affecting third-party hardware, software, firmware, or cloud services should also be reported directly to the applicable vendor.
11. Policy Updates
Sunol Tech LLC reserves the right to update this Vulnerability Disclosure Policy at any time. Updated versions will be published on this page with a revised effective date.
12. Contact Information
Email: [email protected]
Phone: (XXX) XXX-XXXX
Website: www.ParagonNS.com
Report a Security Vulnerability
If you have discovered a security issue affecting Sunol Tech LLC systems, please contact our Security Team through the approved reporting channels.
Contact Security Team