Security & Vulnerability Disclosure Policy
Effective Date: September 19, 2026
Last Updated: September 19, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Commitment to Security
Security is the core foundation of the Startum Identity Platform. We are committed to safeguarding user identity data, protecting OAuth 2.0 authorization flows, and addressing security vulnerabilities promptly and transparently.
We welcome reports from security researchers, ethical hackers, developers, and users who discover potential security issues across our infrastructure, APIs, and client portals.
2. Safe Harbor & Ethical Conduct Guidelines
Startum provides Safe Harbor for security researchers who conduct research and report vulnerabilities in good faith in accordance with this policy. We will not pursue legal action against researchers who comply with the following guidelines:
Do:
- Perform research only against your own accounts or test environments without impacting other users.
- Submit detailed vulnerability reports with clear reproduction steps.
- Maintain strict confidentiality and allow Startum a reasonable timeframe to remediate reported issues before public disclosure (Coordinated Vulnerability Disclosure).
Do Not:
- Execute Denial of Service (DoS / DDoS) attacks or test resource exhaustion.
- Access, download, alter, or delete data belonging to other users or accounts.
- Perform physical attacks, social engineering, or phishing against Startum staff or users.
- Spam authentication or token endpoints with automated scanners.
3. In-Scope & Out-of-Scope Targets
In-Scope Domains & Services:
- Startum Account Portal (
startum.cloud/:4010) - Startum Developer Portal (
develop.startum.cloud/:4011) - Startum Identity & OAuth API (
api.startum.cloud/:4012) - OIDC Discovery & JWKS Endpoints (
.well-known/openid-configuration,.well-known/jwks.json) - SSO Client Button Library (
button.js,startum-button.css)
Out-of-Scope Issues:
- Missing security headers that do not lead to demonstrable exploitation.
- Reports of public IP addresses or non-sensitive banner disclosures.
- Issues relying on outdated or unpatched end-user browsers.
- Social engineering, spam, or physical attack vectors.
4. Reporting a Vulnerability
If you discover a security vulnerability in Startum, please report it immediately by emailing:
Email: [email protected]
Please Include:
- Title & Summary: Brief description of the vulnerability.
- Affected Endpoint / Component: Exact URL, API route, or code file.
- Proof of Concept (PoC): Step-by-step instructions or sample payloads demonstrating the vulnerability.
- Impact Assessment: Explanation of potential risk or data exposure.
5. Response Timelines & Remediation SLA
Startum commits to the following response metrics for security disclosures:
| Stage | Target SLA |
|---|---|
| Initial Acknowledgment | Within 24 hours of receipt |
| Triage & Severity Assessment | Within 48 hours |
| Critical Vulnerability Fix | Within 72 hours |
| High / Medium Vulnerability Fix | Within 7–14 calendar days |
Once remediated, we will notify the researcher and coordinate public disclosure credit if requested.
6. Security Expectations for Integrated Applications
Developers integrating Startum SSO into their applications must adhere to basic platform security requirements:
- Enforce HTTPS on all production authentication callbacks.
- Validate state parameters to protect end users against login CSRF attacks.
- Rotate secrets immediately if a leak or security incident occurs.
7. Contact Information
Email: [email protected]
PGP Key / Security Portal: https://develop.startum.cloud/security-policy