Responsible Disclosure Policy
RESPONSIBLE DISCLOSURE POLICY
1. Introduction
RecallChek is operated by Inspector Services Group, a Porch Group company. If you have discovered a security vulnerability in RecallChek or any Porch Group subsidiary, we encourage you to report it responsibly using the process below. We are committed to working with security researchers to verify and address any potential vulnerabilities in a timely manner.
2. How to Report a Vulnerability
Please send reports to
security@porch.com. You can also find our disclosure details at
/.well-known/security.txt.
To help us evaluate and respond to your report as quickly as possible, please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Supporting materials, such as screenshots, proof-of-concept code, or logs
- The affected URL, endpoint, or system component
3. What to Expect
- We will acknowledge receipt of your report within 2 weeks
- We will assess the severity and impact of the reported issue on an ongoing basis
- Once resolved, we may request your help retesting the fix, and, with your permission, will credit you in our Hall of Fame
4. Findings We Consider Out of Scope
We will close reports that do not demonstrate a real-world security impact, including but not limited to:
Theoretical scenarios: vulnerabilities requiring an unsupported browser or OS, broken link hijacking, tabnabbing, content spoofing, issues requiring physical access to a device, and self-XSS.
No real-world impact: clickjacking without a sensitive action, CSRF on forms with no sensitive action, permissive CORS configuration without a demonstrated impact, software version disclosure, CSV injection, and open redirects without additional demonstrated risk.
Configuration recommendations: SSL/TLS configuration suggestions, missing mobile app protections, cookie flag recommendations, Content Security Policy opinions, email security (SPF/DKIM/DMARC) suggestions, and rate limiting concerns.
Prohibited testing: we do not permit denial of service (DoS/DDoS) testing, any activity that impacts the availability of our systems, social engineering of our employees or contractors, disruptive notifications sent to our users or administrators, or attacks against our physical facilities.
5. Safe Harbor
We consider security research conducted in good faith and in accordance with this policy to be authorized. We will not pursue legal action against researchers who make a good faith effort to comply with this policy. When testing, please limit any access to data to what is minimally necessary to demonstrate a vulnerability, and only use accounts you own or have been explicitly authorized to use.
6. Recognition
RecallChek does not currently offer a paid bug bounty program. Researchers who submit a valid report may, with their permission, be credited in our Hall of Fame. We are evaluating expanding our program in the future.