Vulnerability Reporting Program

Vulnerability Reporting Program

Vulnerability Disclosure Policy

At OneStock, we take security very seriously and value the contributions of the security community. We are committed to maintaining the security and integrity of our platform, services, and customer data. If you believe you have discovered a vulnerability in our systems, we encourage you to report it to us responsibly.

How to Report a Vulnerability

You can report potential vulnerabilities by contacting our security team at:

security at onestock-retail.com

Please include as much information as possible to help us understand and reproduce the issue:

  • A detailed description of the vulnerability

  • The components or endpoints affected

  • Steps to reproduce the issue, including any proof-of-concept code or screenshots

  • Any known impact or potential exploit scenario

What to Expect After Reporting

Once a report is submitted, we commit to the following process:

  • Acknowledgment: We will acknowledge receipt of your report within 3 business days.

  • Assessment: Our security team will assess the validity, severity, and impact of the reported issue.

  • Status Updates: We will provide regular status updates to you during the investigation and resolution process.

  • Resolution: We aim to resolve validated issues according to the timelines below, based on severity.

Severity Classification and Remediation Timelines

We follow the CVSS (Common Vulnerability Scoring System) guidelines to assess severity levels. Based on that, our target remediation timelines are:

Severity Level

Description

Target Time to Remediate

Severity Level

Description

Target Time to Remediate

Critical

Exploitable remotely, significant data exposure or control

within 7 days

High

High risk of data compromise, but limited scope or complexity

within 14 days

Medium

Limited impact or requires specific conditions to exploit

within 30 days

Low

Minor issues with minimal impact or hard to exploit

within 90 days

In cases where remediation requires more time (e.g., due to dependency on third-party components), we will provide transparency about the delay and mitigation steps taken.

Scope

This policy applies to OneStock’s core SaaS platform and services, including public APIs and back-office interfaces. It does not cover third-party platforms or client-managed systems.