Policy
Responsible Vulnerability Reporting Policy
Our Commitment
At Monks, we take the security of our systems, products and services (“assets”) seriously. This Policy is intended solely to provide a mechanism for reporting security vulnerabilities that have been identified through accidental or passive observation. It does not authorize, encourage, or permit security research, vulnerability scanning, penetration testing or any other form of active testing of Monks' assets. This Policy provides a channel for reporting potential vulnerabilities and outlines the expectations applicable to such reports.
Scope
This policy is intended solely to facilitate the responsible reporting of security vulnerabilities.
This policy does not authorize:
- Active penetration testing of Monks assets.
- Unauthorized targeted vulnerability scanning or other active security testing specifically directed at Monks' systems or infrastructure.
- Security testing that may affect the confidentiality, integrity or availability of Monks assets.
- Testing of client-owned, client-managed, or client-hosted systems, environments, or assets operated by or on behalf of Monks.
- Any activity that violates applicable law, contractual obligations or third-party rights.
Unauthorized targeted vulnerability scanning, penetration testing, or other active security testing specifically directed at Monks' systems or infrastructure is prohibited.
Reporting a Vulnerability
If you believe you have identified a security vulnerability affecting a Monks-operated assets, please report it to:
Email: security@monks.com
Subject: Vulnerability External Report – [Brief Description]
To help us investigate efficiently, please include, where possible:
- A description of the vulnerability.
- The affected assets.
- A description of how the issue was identified or observed, including any relevant steps that do not involve active testing or validation prohibited by this Policy.
Supporting information, where appropriate, should be limited to non-executable materials such as screenshots, logs, network traces, configuration snippets, or relevant source code excerpts. Do not send executable files, malware samples, weaponized proof-of-concept code, scripts intended to exploit a vulnerability, or any other file intended to be executed, unless expressly requested by Monks Security and submitted through a secure channel designated by Monks.
Responsible Disclosure Expectations
If you identify a potential security vulnerability during the normal use of our services or through accidental or passive observation, we ask that you:
- Act in good faith
- Do not attempt to validate, exploit, or further investigate the suspected vulnerability through active testing or any intrusive activity.
- Do not access, modify, copy, download, or retain any data that does not belong to you
- If you encounter personal data, confidential information, or client information, immediately cease any activity and report the issue to Monks
- If you become aware that the suspected vulnerability may have unintentionally modified data, include, where possible, the type of data affected, the affected application or endpoint, the relevant request parameters or actions performed, the approximate time of the event, and any identifiers that may assist Monks in locating and restoring the affected data.
- Do not perform unauthorized targeted vulnerability scanning, penetration testing, denial-of-service attacks, phishing, social engineering, malware deployment, or any other activity specifically directed at Monks' or its clients' systems that may affect the confidentiality, integrity, or availability of Monks' or its clients' systems, services, employees, contractors, partners, customers, or third parties.
- Treat any information related to a reported vulnerability as strictly confidential. You must not disclose, publish, or otherwise communicate the existence or details of any vulnerability to any third party without Monks' prior written consent.
Monks' Response
Upon receiving a vulnerability report, Monks will: i) Acknowledge receipt of the report within a reasonable timeframe, ii) Review and assess the reported issue, iii) Determine appropriate remediation based on the nature and severity of the vulnerability, and iv) Communicate with the reporter where appropriate during the investigation.
Submission of a report does not guarantee remediation, public acknowledgement or further communication.
Bug Bounty
Monks does not currently operate a bug bounty or vulnerability reward program. Submission of a vulnerability report does not create any entitlement to compensation or other reward.
Legal Notice
Nothing in this policy authorizes any person to access, test, interfere with or otherwise interact with Monks' systems beyond what is expressly permitted by applicable law. Monks reserves all legal rights with respect to activities that fall outside the scope of this policy or violate applicable law, contractual obligations or this policy.
If you are unsure whether a particular activity falls within the scope of this policy, please contact security@monks.com before proceeding.