Coordinated Vulnerability Disclosure Policy
Our commitment to security and data protection
At Balencio, the protection of our clients’ privacy and the security of our human capital management platform are our absolute priorities. Although we design our ecosystem according to Security and Privacy by Design principles and comply with international security standards (ISO 27001), we acknowledge that the risk of a flaw is never absolute zero.
We consider the cybersecurity research community as a trusted partner to help us proactively identify threats. In accordance with our Penetration testing policy, we encourage anyone discovering a potential vulnerability on our systems to report it to us in an ethical and coordinated manner.
How to report a vulnerability?
If you believe you have identified a security vulnerability on the Balencio platform (app.balencio.io) or our cloud infrastructure, we ask that you report it to us without delay by contacting our Chief Information Security Officer (CISO) and our Data Protection Officer (DPO) at the following address: dataprotection@balencio.com.
To ensure the confidentiality of our communications, we recommend using the TLP (Traffic Light Protocol) standard. By default, we will treat all received vulnerability reports with the TLP:AMBER confidentiality level (information restricted strictly to a need-to-know basis internally for remediation purposes). If the flaw is particularly critical, please feel free to tag your report as TLP:RED (distribution strictly limited to the direct recipients of the email).
To help us validate and patch the issue as quickly as possible, please include in your report:
- A detailed description of the vulnerability and its potential impact.
- The precise steps required to reproduce it (Proof of Concept – PoC).
- A suggested evaluation score according to the international CVSS standard (Common Vulnerability Scoring System, version 2 or 3).
Responsible disclosure guidelines (safe harbor)
To encourage security research while protecting our clients’ data, we require you to strictly respect the following rules during your investigations:
- Never access, modify, destroy, or exfiltrate our clients’ data or the personal data of our users.
- Do not exploit the vulnerability beyond what is strictly necessary to prove its existence (Proof of Concept).
- Do not disrupt the availability of our services (Denial of Service attacks, such as DoS/DDoS, or spamming are strictly prohibited).
- Keep the details of the vulnerability strictly confidential until we have had sufficient time to deploy the necessary patch.
If you conduct your research in good faith and in full compliance with this policy, Balencio commits to not taking any legal or disciplinary action against you.
Our evaluation process and remediation timeframes
Upon receipt of your report, our engineering team and our CISO commit to evaluating it promptly. All identified vulnerabilities are analyzed and scored according to the CVSS standard, and any potential false positives are subject to an internal arbitration process.
We sincerely thank you for your contribution to the security of the Balencio environment and the protection of our clients’ data.