Vulnerability Disclosure Policy
生效日期: 2026-03-01
公司: Asteria Limited (HK)
This Vulnerability Disclosure Policy explains how security researchers, customers, users, and the public may report suspected security vulnerabilities affecting ASTERIA KYC systems, website, APIs, SDKs, dashboards, infrastructure, or related services.
ASTERIA KYC values responsible security research. This policy is intended to encourage good-faith reporting while protecting customers, end users, systems, data, and service availability.
This policy does not grant permission to conduct intrusive, disruptive, destructive, or unauthorized testing.
1. Purpose
The purpose of this policy is to:
- provide a safe channel for reporting suspected vulnerabilities
- encourage responsible disclosure
- protect Customer Data and End User data
- reduce security risk
- support timely investigation and remediation
- define prohibited testing activity
- establish expectations for communications
2. Good-Faith Research
Good-faith research means security testing that is designed to identify vulnerabilities without causing harm, accessing data without authorization, disrupting services, degrading performance, violating privacy, bypassing legal restrictions, or exploiting vulnerabilities beyond what is necessary to demonstrate the issue.
Researchers must act responsibly, lawfully, and ethically.
3. Scope
This policy may apply to publicly accessible ASTERIA KYC web assets, public pages, public documentation, and other systems explicitly identified by ASTERIA KYC as eligible for testing.
Unless expressly authorized in writing, the following are not in scope:
- Customer environments
- Customer accounts
- Customer data
- End User data
- production dashboards requiring authentication
- non-public APIs
- employee systems
- internal infrastructure
- third-party systems
- social engineering targets
- physical premises
- vendor systems
- systems not owned or controlled by ASTERIA KYC
4. Prohibited Activities
You must not:
- access, view, copy, modify, delete, or exfiltrate Customer Data or End User data
- conduct denial-of-service or load testing
- perform destructive testing
- deploy malware
- use ransomware or extortion techniques
- perform phishing or social engineering
- attack employees, contractors, customers, or vendors
- attempt physical intrusion
- bypass rate limits in a way that affects availability
- alter data
- persist in systems
- install backdoors
- pivot to other systems
- use stolen credentials
- test third-party systems without permission
- publicly disclose vulnerabilities before ASTERIA KYC has had a reasonable opportunity to investigate and remediate
- use vulnerability findings for coercion, threats, or commercial pressure
- violate applicable law
5. Handling Sensitive Data
If you accidentally access personal data, Customer Data, credentials, tokens, secrets, private keys, identity documents, biometric-related data, financial data, or other sensitive information:
- stop testing immediately
- do not save, copy, transfer, share, or disclose the data
- report the incident immediately
- include only the minimum information necessary to help ASTERIA KYC identify and remediate the issue
- delete any inadvertently obtained data after receiving confirmation or instruction from ASTERIA KYC
6. Reporting a Vulnerability
A vulnerability report should include:
- a clear description of the issue
- affected URL, endpoint, page, API, SDK, or component
- steps to reproduce
- evidence such as screenshots or logs, without exposing sensitive data
- potential impact
- suggested remediation if available
- date and time of discovery
- researcher contact information
- any limitations or special conditions needed to reproduce the issue
Reports should be sent through the official contact channel provided on the ASTERIA KYC website.
7. What to Avoid in Reports
Do not include:
- personal data of real End Users
- identity documents
- biometric images
- Customer confidential information
- secrets or credentials in plain text unless necessary and safely redacted
- exploit code that enables broad abuse
- unnecessary screenshots of sensitive data
- public disclosure links before coordinated resolution
8. Our Response Process
After receiving a vulnerability report, ASTERIA KYC may:
- acknowledge receipt
- review the report
- request additional information
- reproduce the issue
- assess severity
- prioritize remediation
- implement a fix or mitigation
- validate remediation
- communicate status where appropriate
- close the report when resolved or determined not applicable
Response timelines may vary depending on severity, complexity, affected systems, third-party involvement, and operational priorities.
9. No Compensation Commitment
This policy does not create a bug bounty program and does not guarantee compensation, reward, employment, contract opportunity, public credit, or reimbursement.
Any recognition or reward is at ASTERIA KYC’s sole discretion and must be agreed in writing.
10. Public Disclosure
Researchers must not publicly disclose vulnerabilities, technical details, exploit methods, screenshots, or proof-of-concept materials before ASTERIA KYC has had a reasonable opportunity to investigate and remediate.
Coordinated public disclosure may be considered only after written agreement with ASTERIA KYC.
11. Legal Safe Harbor
ASTERIA KYC intends to avoid legal action against researchers who comply with this policy, act in good faith, avoid harm, respect privacy, and report vulnerabilities responsibly.
This does not protect activity that is unlawful, harmful, destructive, extortionate, privacy-invasive, or outside the scope of this policy.
12. Severity Considerations
ASTERIA KYC may assess severity based on factors such as:
- impact on confidentiality
- impact on integrity
- impact on availability
- ability to access Customer Data
- ability to access End User data
- authentication bypass
- privilege escalation
- exploitability
- affected user count
- affected systems
- required attacker skill
- presence of mitigating controls
13. Out-of-Scope Findings
The following are generally out of scope unless they lead to a demonstrated security impact:
- missing security headers without exploitability
- generic best-practice observations
- clickjacking on pages with no sensitive actions
- rate-limit concerns without meaningful abuse impact
- outdated software disclosure without exploitability
- self-XSS
- SPF, DKIM, or DMARC issues without demonstrated risk
- social engineering
- physical security findings
- automated scanner output without validation
- denial-of-service findings
- issues affecting third-party services only
14. Customer and Third-Party Systems
Do not test Customer systems, Customer accounts, third-party integrations, vendors, subprocessors, or partner platforms unless you have explicit permission from the relevant owner.
ASTERIA KYC is not responsible for unauthorized testing of third-party systems.
15. Researcher Conduct
Researchers must:
- act professionally
- avoid privacy invasion
- minimize testing impact
- stop immediately if harm may occur
- follow ASTERIA KYC instructions
- keep findings confidential
- communicate clearly
- avoid extortion or pressure tactics
- comply with law
16. Updates to This Policy
ASTERIA KYC may update this Vulnerability Disclosure Policy from time to time. Updated versions will be posted on the website with a revised effective date.
对本政策有任何疑问?
如您对本政策、ASTERIA KYC 服务、数据处理、合规工作流程或相关文档有任何问题,请通过网站上提供的官方联系渠道与 Asteria 联系。