AdvanPath welcomes good-faith reports about suspected vulnerabilities affecting its public website. This page provides a reporting route and clarifies the limits of any security research. It does not authorize testing against client systems, client data, service-delivery environments, suppliers, or infrastructure not owned or controlled by AdvanPath.
1. Security contact
Email suspected website vulnerabilities to security@advanpath.com. The same contact is published in AdvanPath's security.txt file.
Do not include passwords, authentication tokens, private keys, regulated data, client information, or personal information beyond what is necessary to explain the issue. If sensitive evidence is required, ask for an appropriate transfer method first.
2. Scope
The reporting channel is intended for suspected security issues affecting advanpath.com, its public website assets, and the public contact-form endpoint operated by AdvanPath.
The word "scope" identifies the systems for which AdvanPath accepts reports. It does not authorize testing, access, or any activity that would otherwise be unauthorized. Prior written permission is required for any action that would otherwise require authorization.
Reports concerning the following systems or targets are not accepted through this public reporting invitation unless AdvanPath provides prior written authorization:
- client systems, client accounts, client data, or client-service environments;
- Cloudflare, email providers, telecommunications, or other independent third-party services;
- employee, contractor, supplier, or personal devices and accounts;
- physical offices, field locations, records, or social-engineering targets; and
- systems that merely share a name, domain reference, supplier, or network relationship with AdvanPath.
3. What to include in a report
A useful report generally includes:
- the affected URL, endpoint, asset, or feature;
- a concise description of the suspected vulnerability and potential impact;
- the steps needed to reproduce the issue using the minimum activity necessary;
- the date and time of testing and relevant browser, device, or request details;
- sanitized screenshots, request examples, or other evidence where helpful; and
- a reliable way for AdvanPath to contact the reporter with questions.
Do not publicly disclose an unresolved issue or share exploit details with third parties before AdvanPath has had a reasonable opportunity to review and respond.
4. Security research boundaries
This page does not grant authorization to test or access systems, waive legal rights, create a safe-harbor commitment, or establish a bug-bounty program. Researchers remain responsible for obtaining any required permission, complying with law, and avoiding harm.
Do not:
- access, alter, copy, download, retain, or disclose another person's or organization's data;
- perform denial-of-service, load, stress, volumetric, resource-exhaustion, or destructive testing;
- use social engineering, phishing, credential attacks, malware, physical access, or third-party compromise;
- create persistence, move laterally, escalate beyond the minimum proof, or attempt to evade monitoring;
- automate high-volume scanning or submit repetitive reports without prior written authorization; or
- interfere with website availability, contact-form delivery, security controls, or other users.
If testing reveals data or access beyond the minimum needed to demonstrate the issue, stop, preserve only the minimum information needed to report it, and contact AdvanPath.
5. What happens after a report
AdvanPath will route the report for review and may request clarification, sanitized evidence, or a coordinated way to validate the issue. Response and remediation timing depends on severity, reproducibility, affected systems, provider dependencies, legal requirements, and the availability of a safe correction.
Submitting a report does not create an employment, agency, contractual, confidential, fiduciary, or professional relationship and does not entitle the reporter to payment, public credit, or another reward. Any acknowledgment or disclosure arrangement must be agreed separately in writing.
6. Changes to this page
AdvanPath may update the reporting channel, scope, or research boundaries as the website and its providers change. The last-updated date identifies the current version.