Responsible Disclosure Policy
How to report a security vulnerability in intellinksea.com and what you can expect from us.
1. Our Commitment
At Intellinks East Africa, we are committed to the security of our website and of the data you entrust to us. As a cybersecurity solutions provider, we believe that coordinated, responsible disclosure is the right way to improve the security of our systems. We welcome the efforts of security researchers who help us keep intellinksea.com and its visitors safe.
2. Reporting a Vulnerability
If you believe you have discovered a security vulnerability in intellinksea.com, please report it to us privately before disclosing it publicly. Email your findings to:
To help us respond effectively, please include:
- A description of the vulnerability and the affected page/endpoint;
- Steps to reproduce the issue (including any test accounts or request details);
- Your assessment of the potential impact; and
- Your contact details for follow-up (if you wish).
What you can expect:
- We will acknowledge receipt of your report within three (3) business days;
- We will provide an initial triage/assessment and remediation timeline within ten (10) business days;
- We will provide progress updates at least every two (2) weeks while the issue remains open; and
- We commit to coordinated disclosure: we will not publicly disclose a vulnerability until you have had the opportunity to fix it, and we will make no public announcement before ninety (90) days from the date of report, unless the issue has already been fixed or is being actively exploited.
3. What We Ask of You
When researching or reporting vulnerabilities, please:
- Do not access, modify, or exfiltrate data you do not own; limit testing to proof-of-concept on a single account/piece of data;
- Do not perform denial-of-service attacks, spam, or brute-force activity that degrades service for other users;
- Do not use automated vulnerability scanners against the Site without prior written authorization from us;
- Do not publicly disclose details of a vulnerability until we have had a reasonable opportunity to fix it (typically 90 days); and
- Act in good faith and in accordance with Kenyan law, including the Computer Misuse and Cybercrimes Act, 2018.
4. What You Can Expect From Us
- Prompt acknowledgement of your report within 3 business days and a named security contact;
- An initial triage and good-faith assessment of the report’s validity and impact within 10 business days;
- Where a report is valid, a remediation commitment with a target timeline, with progress updates at least every 2 weeks;
- A commitment to 90-day coordinated disclosure before any public announcement;
- Credit for your contribution (with your permission) in any public acknowledgement of the issue.
We do not currently operate a public bug-bounty (financial reward) programme. To the extent permitted by law, we will not pursue legal action against researchers who engage in testing strictly in accordance with this policy and in good faith.
5. Out of Scope
The following are generally out of scope and should not be tested without prior written agreement:
- Third-party services and client systems linked from this Site;
- Physical, social-engineering, or phishing attacks against Intellinks staff;
- Attacks on infrastructure other than the intellinksea.com web application itself.
6. Security.txt
This policy is also published in machine-readable form at /.well-known/security.txt (and mirrored at /security.txt) in line with the IETF security.txt standard.
7. Contact
Security contact: security@intellinksea.com
Intellinks East Africa Limited, Vision Plaza, 5th Floor, Suite 18, Mombasa Road, Nairobi, Kenya.