Vulnerability Reporting Program
Vulnerability Disclosure Policy
At OneStock, we take security very seriously and value the contributions of the security community. We are committed to maintaining the security and integrity of our platform, services, and customer data. If you believe you have discovered a vulnerability in our systems, we encourage you to report it to us responsibly.
How to Report a Vulnerability
You can report potential vulnerabilities by contacting our security team at:
security at onestock-retail.com
Please include as much information as possible to help us understand and reproduce the issue:
A detailed description of the vulnerability
The components or endpoints affected
Steps to reproduce the issue, including any proof-of-concept code or screenshots
Any known impact or potential exploit scenario
What to Expect After Reporting
Once a report is submitted, we commit to the following process:
Acknowledgment: We will acknowledge receipt of your report within 3 business days.
Assessment: Our security team will assess the validity, severity, and impact of the reported issue.
Status Updates: We will provide regular status updates to you during the investigation and resolution process.
Resolution: We aim to resolve validated issues according to the timelines below, based on severity.
Severity Classification and Remediation Timelines
We follow the CVSS (Common Vulnerability Scoring System) guidelines to assess severity levels. Based on that, our target remediation timelines are:
Severity Level | Description | Target Time to Remediate |
|---|---|---|
Critical | Exploitable remotely, significant data exposure or control | within 7 days |
High | High risk of data compromise, but limited scope or complexity | within 14 days |
Medium | Limited impact or requires specific conditions to exploit | within 30 days |
Low | Minor issues with minimal impact or hard to exploit | within 90 days |
In cases where remediation requires more time (e.g., due to dependency on third-party components), we will provide transparency about the delay and mitigation steps taken.
Scope
This policy applies to OneStock’s core SaaS platform and services, including public APIs and back-office interfaces. It does not cover third-party platforms or client-managed systems.