Security Center
Vulnerability disclosure
If you believe you have found a security vulnerability in a SecurePoint USA service, we want to hear about it. This page says how to reach us, what we ask of you, and what you can expect from us.
How to report
Email security@securepointusa.com. Include the affected URL or component, steps to reproduce, and the impact you believe it has. Screenshots or a proof of concept help; a working exploit is not required. This address is also published at /.well-known/security.txt.
In scope
- www.securepointusa.com and app.securepointusa.com
- The public screening API under /api/v1
- Visitor kiosk, check-in, and host portal surfaces served from those domains
Third-party services we rely on (hosting, database, identity, email) have their own disclosure programs. Findings in those platforms belong with those vendors; if you are unsure, send it to us and we will route it.
What we ask
- Do not access, modify, or exfiltrate data that is not your own. If you encounter another organization's data, stop and tell us.
- Do not run denial-of-service, spam, or social-engineering tests against our staff or customers.
- Do not use automated scanners against the production kiosk or check-in surfaces; they serve live facilities.
- Give us a reasonable time to fix the issue before disclosing it publicly.
What you can expect
- An acknowledgement from a person, not an autoresponder.
- Triage by severity and a fix prioritized against our documented remediation targets.
- Updates as the issue moves, and notice when it is resolved.
- Credit, if you want it, once the fix is live.
- No legal action against researchers who follow this policy in good faith.
We do not currently operate a paid bounty program.
For the wider security posture, controls, and downloadable evidence, see the Security Center.