Vulnerability Disclosure Policy
Effective Date: June 16, 2026 | Last Updated: June 16, 2026
Vulnerability Disclosure Policy
In short: We take the security of our customers' data seriously, and we welcome reports from security researchers who find genuine issues. This page explains how to report a vulnerability, what is in scope, and what you can expect from us in return.
ExecutivePulse does not operate a paid bug bounty program. We do not offer monetary rewards, and we do not respond to unsolicited offers, rewards solicitations, or "I found a problem, pay me to see it" messages. Genuine, good-faith reports are always read and acted on.
1. How to Report a Vulnerability
If you believe you have found a security vulnerability in an ExecutivePulse system, please email Support@e-pulse.net. To help us investigate quickly, please include:
- A clear description of the issue and its potential impact
- The affected URL, page, or component
- The steps needed to reproduce it, including any sample requests or proof-of-concept
- Your name or handle, if you would like to be credited
Please give us a reasonable opportunity to investigate and remediate before disclosing the issue publicly or to any third party. We are committed to working with you in good faith.
2. Scope
The following are in scope for security research under this policy:
- Our marketing website at www.executivepulse.com
- Our application at e-pulse.net and www.executivepulse.net
When you test, please use only accounts and data that belong to you. Do not access, modify, or delete data that is not yours, and stop as soon as you confirm a vulnerability exists.
3. Out of Scope
The following activities and report types are not covered by this policy and are not considered valid reports:
- Denial-of-service or volumetric attacks, load testing, or anything that degrades service for our customers
- Social engineering of our staff, customers, or vendors, and physical attacks against our facilities
- Spam, phishing, or unsolicited messages sent to our addresses
- Automated scanner output submitted without a working proof-of-concept
- Reports that consist only of missing best-practice headers or configuration suggestions with no demonstrated impact
4. Good-Faith Safe Harbor
If you make a good-faith effort to follow this policy during your research, we will consider your activity authorized, we will not pursue legal action against you, and we will work with you to understand and resolve the issue quickly. This safe harbor does not apply to activity that violates the law or that accesses, harms, or exposes the data of our customers or other users.
5. What to Expect From Us
- We aim to acknowledge valid reports within five business days
- We will keep you informed as we investigate and work toward a fix
- When a finding is confirmed, we are glad to publicly credit the researcher who reported it, with your permission
We do not offer monetary compensation for reports. Recognition and a fixed product are what we can offer in return for responsible disclosure.
Frequently Asked Questions
How do I report a security vulnerability to ExecutivePulse?
Email Support@e-pulse.net with a clear description of the issue, the affected URL or component, and the steps needed to reproduce it. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.
Does ExecutivePulse pay rewards for security reports?
No. ExecutivePulse does not operate a paid bug bounty program and does not offer monetary rewards. We do read and act on genuine, good-faith reports, and we are glad to credit researchers who report responsibly when a finding is confirmed.
What is in scope for security research?
The ExecutivePulse marketing site at www.executivepulse.com and the ExecutivePulse application at e-pulse.net are in scope. Testing must not degrade service for customers, must not access or modify data that is not your own, and must not use denial-of-service or social-engineering techniques.
6. Contact
For all security matters, please reach our security contact directly. A machine-readable version of this contact information is published at /.well-known/security.txt in line with RFC 9116.
ExecutivePulse Security Contact
Email: Support@e-pulse.net
Phone: 866-397-8573
Address: 155 East 10th, Erie, PA 16501
