The primary objective of this Vulnerability Disclosure Policy (the "Policy") is to ensure the timely identification, verification, and resolution of security vulnerabilities in our clients' codebases. At Asterisk, we believe in responsible disclosure and collaborative efforts to enhance the overall security posture of our clients and the broader community.
This Policy applies to all vulnerabilities discovered by Asterisk's AI-augmented security audit system in client codebases. It outlines the processes for initial contact, vulnerability verification, and public disclosure.
Upon discovery of a potential vulnerability, Asterisk will:
If we do not receive a response within 48 hours, we will make a second attempt. If there is no response after 72 hours, we will escalate to an alternative contact provided during the onboarding process.
Once contact is established:
Asterisk is committed to supporting our clients throughout the remediation process:
Asterisk follows a responsible disclosure timeline:
Asterisk treats all vulnerability information as confidential until public disclosure is agreed upon with the client. We do not share vulnerability details with third parties without explicit client consent.
Asterisk operates under the principle of good faith. We expect our clients to refrain from taking legal action against us for our security research and vulnerability disclosure efforts, provided we act in accordance with this Policy.
For any questions or concerns regarding this Policy or to report a vulnerability, please contact our security team at security@asterisk.so.
Asterisk reserves the right to modify this Policy at any time.