Responsible Disclosure

configure8 is committed to ensuring the security of our systems and protecting our users’ data. We appreciate the efforts of security researchers who help us identify and fix vulnerabilities in our systems. We do not take legal action against researchers who report vulnerabilities to us in a responsible and ethical manner, following the guidelines below. We handle all reports with utmost urgency and care.

Guidelines

  • Please respect the privacy and integrity of our systems and data during your testing. This means you should not perform any actions that could compromise or damage our production systems, affect their availability, or violate our users’ privacy.
  • Do not use brute-force or spamming tactics nor automated vulnerability scanning tools on our systems. These methods are noisy and ineffective, and may interfere with our normal operations.
  • Never exploit a vulnerability you discover to access, modify, or delete data that does not belong to you.
  • Please keep the details of any vulnerability you find confidential between you and configure8 until we fix the issue. We will work hard to resolve the issue as quickly as possible.

Scope

Our Responsible Disclosure Program encompasses app.configure8.io.

Vulnerability Submissions

Please report any security issues you find to security@configure8.io. If your submission contains any sensitive vulnerability information, please encrypt it using our PGP public key at the bottom of this page.

Ensure your submission includes the following:

  • Your name and contact information;
  • Company name (if applicable);
  • A detailed description of the potential vulnerability;
  • Detailed steps to reproduce the issue, including any associated URL and parameters demonstrating the vulnerability;
  • Any relevant details of your system’s configuration, such as any browser or user-agent information; and,
  • Your IP address and the email address used to create your account.

Reward

We may offer a reward to thank you for reporting a valid vulnerability to us. The reward amount will depend on the severity, impact, and uniqueness of the vulnerability. We will review each submission individually and decide whether to offer a reward and how much. Our decision is final and non-negotiable.

Thank You

We are grateful for your responsible disclosure and your collaboration with us to enhance our security! We recognize the skills and efforts you have invested in finding these issues and contacting us. Thank you for making the configure8 a safer application.

PGP Key

If you need to share confidential details about a vulnerability or prefer to communicate with us securely, you can use the PGP key below to encrypt your message to us.

Copy To Clipboard
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: Keybase OpenPGP v1.0.0
Comment: https://keybase.io/crypto

xsFNBGSRwgkBEACXY4fNAOBXDzw9kgCMJBPgjXf9ThBDwSbWryvbAg8lw+PWvZwM
yqFgsX2B/LZLUhrsJe81rEPKeuBrg0lIg2UWnI3MRLDG+mWI6BRgJX/5mbhRUCyE
AANq/IEm1lg6Lq1gx4lIA/Kn25DOv5v3qUh9g6dCbrm/yfTLqbMKYxPW9big0oix
vpckXqyJwqc/8M67oLlfv5/TVaNElp7JCk2z09OXpg6bGKUcvRWDT9XAa74/5aVA
nZaUQRVQzguiRWbMd9mEymYfXshBywDxKhvQgUz/M6Qpw0BwcxjnH1+A4A4zUNGI
waQFPrj4gejbIM4dOoreEDP4DD4eBtKqYFYZ3j244jjTXtRl94a3XRu1vPlmR2v4
SScS77qVk0+sjnEMeEvSVfbo0/COCVOS9VGN3wPkf+p6efpEW5tvLJwh3VE5AJaR
V1ZchkkWinlG6QhThOG12yK1RlJEdgq3C8i59gORF1Xb63+9nIr65Qune4PQRDVd
frN8Tc6edXIce2jrCMeWQpohhBnA/gW04nDI+9L9MddV5UDiyZJ5L5HwibQJdHkF
HCsm944Y+cvPRFeS4bFGeFLdUROistL0JIZ+xSGFKaJn8LH1Jeyz+U27CpV1qyt1
bvKw4uKwadEXkIh7N5kefwLDOi2XWq0v0rQrtv1kAb3/wfqWi6wAmkkWmwARAQAB
zR9KYXkgQ3J5c3RhbCA8amF5QGNvbmZpZ3VyZTguaW8+wsFtBBMBCgAXBQJkkcIJ
AhsvAwsJBwMVCggCHgECF4AACgkQ25ZBPV6zFpj9YA/9H2k6BzztXYKyOPxs31kM
4ILgUL1h0f5/nTZyE/QSzbFQs02sYLwEhTQpESUu06BbiPZ0gv9jmGw7fvKT6B7C
ncVinMLpBB4tZoqAHxym/OnoNwKdRkE3osMFLxcAq4Di+ZpA0ns4NICdZ63W0afO
n9U5AmhfvyQJCqQx6IRw2INjxxgWdTymWUzoEipXanY59aEgaPiCOIbxpgCCto4g
NlJwAAulpYWYhpDKSQwN/b/GegjJH0JBWY0/xJg/Ad+QhiEcxCkeBjdNsy/adxyk
/+xvRVnKIixlqzVse8t9O/pFR7tRFD6NnC8rAwriWeWabnogFCYbTNpw070teNgg
Kw8YTa7txxxJPZ46L0T7UhGCJAMIJMca3MkGTDew4KtSk6v8AQFsY21UeXwfAETp
m1FPxOpqloM/uLMODNqXYlOwibJjl4Gf29+7aHJJ6b6PRtMDUcZzHAEALCUsp1AS
9LKcoru3TWqIyojFSleKBFPo9l36UZHfZaoBWAbDF8k0oWRTFY0Iu/2SR+XeHxC+
d0SupVg1FUVErAoDeR9jjmd8k6/kZEBJPt7Lun0iSVCx4zzv1PekTNanTEatIqSG
Lh4/Gow36gV2It0YHBx0zxmnpannPSXrkuKErPFXuNATgKW1174LTluv+rblDiIT
jL0lLNgn6x5D7z+wAME61xjOwU0EZJHCCQEQAPDx4foAVUN46psU7A+CSvxMIt3f
pj/DnQU1CuoXiVmarBZT80FCqhRBcuISRrbangISXCd/R3lie+S9paHqRMPQLx0I
VPQBYm+UuNIhtptRFyCbdr7emG77v6pUsZNhLdM9QV+k58vYzmQt3RuUtvDjhgFZ
tMjWiPzAEexzTISp1FyiUyPIFxXXoD2ZDwZRGSlIZE3I4+3uvW2GIT/UD6gPl7Zy
wO4P4jjevFUIreEU06ygFd/sOGRRl9HFotc2n5zPFBqkaRheNTdVpO5LXw6ZOMy8
bvmGk1lniFth5XphYB5ckBTNeOfVeLKkyeRwJAtgWi2BviQHWDUwVF/PLxAlY46X
dvPuj9bpf1c6KGU542QxnyRpYAld+Nyqc6Xsgp6pyH39Iw/W3UUNm6qX3YPYH3VX
bPiiEYQUc0xG8L33hpw4W3TZWxfCcSYv2141oyCsoLJ+txnYpUCStfIdwx2TZWvE
fzmCpHVu/S6ORT9YTP3ochUcc8w+8iwSCrvha4p2ABDHxvBM4AZjAJNG55SA7iHn
lrd6rw1jF0odez5/oLkDawVphikjf8fpmAbRRTWK2XLy25VLtpPNsVRqBvwyybRj
Td7r0hOcJuFZ80SOKyM2XD01LQPVA5FmGl1a4TewQIiIwMF4Tg+G+7LszEPXx9K7
zFoS982LAR/cHwB/ABEBAAHCw4QEGAEKAA8FAmSRwgkFCQ8JnAACGy4CKQkQ25ZB
PV6zFpjBXSAEGQEKAAYFAmSRwgkACgkQUVYvPfV90M/0uQ/9EvcoLYP0EvApVJhc
lSgfFh/At04mSO4YUyN367Wgl/E+aTLAwG+CiZwDYmlU067EVW7L0xu4IZSi3E5u
CPlo7UO4TSa0EVQWO9obVtisQ9Wie64mWyvhaNYV/F2oZlPTTq5PzS3o7IaoZcfS
u7cdyIxt8hQmi2pc+rYP2GFBM6g1z0lIcp2xFv7KOCUOt/qJicqQv9Efjp/XeZqB
g3sTZsYIDHkG4GYC020sRF94nhSU/0VAoTJvRZq85gyVW6DdsuzDbswzhY1ePZn0
M3vLNe2ObCoZGH7YGLt3WmVJKDLcdxXgZLC8Pk7KyV/PAp2ioIau2x1enEdCDXY9
cGPIFSx464jxj3eHoOoP6Li7mcJuPQQ8I19qdKUwuHOZXIJgqy9kJhMIxW7aFvpV
2m3VxDKdEcmJxnDU+WPDMKW+boxy2g7pTLaoxC0QUWPoxkB4jMtKpKMyNNuUpbAD
L166u6ShtETRZgS97E7eEAuzYYzibLa1L4tWyJA2Ny1BecF5ZZXNe6pMzOEobjRZ
Ro2ARrQTdA8Xoucc0jPdtmDo5c1XWB2QfMKJtVUvTmjWYuy4eaNO/8u8KHclEkek
oVjF1JKfRNkfSPG4QiHfjTHzM6Rh9BPB8VaFDvRIMcc2tX3R1Q9MsleNhDNp4CI3
M8e7orWWobN66kHpU2T3zP1p/4jSvA/+Iv7cr1uGAHqPAhoEhaJVM31v+qGtWalJ
xSuec45elsHfSD9GizJQMbdB2Rb0LFJiSa6hC3t3/iagaV60crSs4qE4kW1HvWgr
pT/ueszUVIUm6qtWGq+0dIb6sSDY1WxOn/0dKoHkVyyLNZMDmZeyzdxqt3RwNawJ
h3WWBNthyPLQ11A7Egz1iuIZxZhCi9g5YoNmR2E89NsN/4B8sz4n9yiZFBU+maLV
loGo/QS7hs26mh5Rq4TSbcJOtaroSVL6XKiqeYiSCpciZYvvOTaqPU2qLjTfiBJj
cO0GF/jYTC+fqvtxhM4FN0s/g53kzm1XAVxWk9AyySFfz3yNdOmrNWppUH3rKPv2
UZTZbgGDC++UZrOTvCkiTUGRFjkXCRHkLtgMAa+WvDlcCKKNLadxSxKK6+t5NC80
26/snDBGh9X8hGRgrszZjuKaFgSmw3W6Oscn7/2tFHtP4YeEJss6d9umOQW7ZxNu
NIghg6zf4Hu06oXK1cY0IFHetWV2eKG9mNoEWkKbZYrLY5CEoahwZqyPCIZEq3tu
Uxww6A1MQiGp/9zc8rscoR5Gbstu5Z9FhMVbjgpRmCUeI0SgPJ/AUomspkN6vi1v
agHiK2nLB4CsFp7QnvILIT1/tpIY48cNzof/8ckICQkcPJOPa2p0h2kGbUt27DQJ
Wny7FGq34ifOwU0EZJHCCQEQAKqdN7W2Iy8aKhRB2cVHEdg9k7QzQxA5OyLxCer6
ry6Dc/6lZnVL0qmbEe79agHeDUFGJOYWe+sJB4fIg7xtwxb+gX/dd2POW4HfTBk7
cM7d3YBzWOf524+/cytJ2RioZ8k/fGUcb1pWXssjHU7GFdeWY2CGG7rD549jUP+C
f1VxX+AEchRAtbPOTDoIKit0sWuJ8WKxiunu91y9x/c7PQ70eFZ5ya79JnOzgFGS
wOO5pkeyB7X9wW/EMrHhlWDHwCNuLkcpQpdq4A0Jk9+7u4IbCSqKiRM7CNpv/C+a
GiSPQBymH9RXuvhdqjcl5on5UQhb/JWCZyjutN52oDMGXXSKcZuf6KZ1StsMWg3R
NOhM78VBQA3nI/jc/1B+SEFELXquYOfQ50PSYb7saish/O2dMmJ7NWJ27T88m4xb
Nv1lnzzFEXmOkzODpTKmNxO8WVjAKaUQYld1zHrbLijTxZZLLD/9P6W36y+zCyCW
DDstvPDtWtwKceHGIPH+Dpe+PEa6uVGrkiAizXbfftl0Y8RYKdjLyhwbiFFGIS+T
6lO91ONbF59ilWzav+6afizUy17BYVCofH/yTnUxGBDIyCgEsabn+MqpnkXCG/my
/FlTA+jzo0LlQB+waT95GsZKM22hzyUeIGOSPKHYPS8j34umCKHWzG29gmVqjyWs
hk6TABEBAAHCw4QEGAEKAA8FAmSRwgkFCQ8JnAACGy4CKQkQ25ZBPV6zFpjBXSAE
GQEKAAYFAmSRwgkACgkQVo53tvdDXHmlOw/7BfSDfMXUtGckAhtP4jPKAoSeS7h0
uxYWd6J2IQ36ZIaAsHCPZ7YAApQ17pIQaeow5NDvF1GL8BeHcOL5UWsabWeoKumh
SmZ3SbSTiiOx2plwwb+q23fm9jzg1eQ0BkhVN55pRHSfeKKqN4L0JHhCvCUTovK3
dSP5Y/MYb2f9iu8rCMTiG/Y4L3InSYXwyeKesksU6dAQjfkOsV4UtAEsQBEvF3lo
Jpr/LYzV7nAhfDT+CCaGh1U986ETdk2alsmWpEbCQgTa77V4sSumf3oqzWiFkCSi
oFInP498VCDgC4WIPxUAYWSRZIDtKtDPWPs4549raJuGkqW0reuj3IsLZ06k4qox
EkARm00n1IIMMYfsQsXMJB2JWJLMgvMWK1FOlUri6GVxdr0qWh8TF77dZ6sr+CaT
ITfyeuE9M/RA+sPR1/UueVjCEG3uLGoN7Tbb3Yiq0nV9tdsdY2UTWyveW5n6Z/Mq
ZGBpt3jy9Wkwaqtd4Kb6hZoI/YUjhk7TzifL+eSCBC6Ii2A4uMw5HL+M4YAFEF+T
79ldAQRr4meTbBdrT/0QBfp/tJXAMCIOEdRD8Y+Z1CfBSb4rU3zp6/MMVvbuRVmS
espkcTSivz6wmw+KSkdB1eJcL7bzvTIXKZ3SuJl6s2CcUYgjvctx9nkcQWhLarc5
K2YYTCUS0rUVOSqwsw/+Oa6dI6SR3iU82QfUTapy4jdiuxGXFyp4nI3LlJEuckyM
5gi9JAySCOkYs7PJakhxkXxfUbJf4crI620P864G/ldnpll4fWE6nf2JAfvE8i7G
/X1vsG2QMdfpMYLk80xncMh9Gie00Lbo1Fk2J1WsvWqE5MaephbkPgAzBaahqsWp
H/aSyv55NF9KixQlKm5blt4kRu1KEG91aSwQrvUazLCtKXr2xRS3BCd2bqm8T59a
b1G6PTQYG+wyKTcKD/qZmnuqCMVWZpxmDnppm8wDw0chRhb3zl7uLIChdPd359P+
pUM/2PcjWBOyKirxhAe2RccUUYtu4oIi9dJTmxlh5LK6cJR+OYdKYemZDe8lhZEd
ZIW5DV7Gu4X1qa8PFjUdXyGBFtFZ/CX1EfoJu5gCAy8Qpg1qiLCgALq8kZm6DKFl
7mnYnSBTje6g0wAVjQaTamQVhH4u4Tbn51JBFTLi7cU63dHfhfBNHWlwRNEVu2c5
MFiduUK/0/xar3HeulTyhhYTm9PngJCkMhpvMpr5mQ3aeY0pCcaD709SlqGL7GNA
uKuHHR13/zFHPfJxF/ZqyfYpndlx59Pm1zZe7p0nvwtogD2oO1SWafY+NbcNMvD2
OovSGuvxYQhg4uiwsgHfJnQ6oi01IJI27G7KcnYVswLmH4/i6CXcjhXKssU+6mg=
=kZ1m
-----END PGP PUBLIC KEY BLOCK-----