1. In-scope systems
This policy applies to publicly accessible systems operated by StackResolve at uptimebasics.com, its application and API subdomains, and stackresolvehq.com. It does not authorize testing of customer-monitored websites, customer custom domains, status pages not operated by StackResolve, provider infrastructure, employee or customer devices, or any third-party service.
If ownership is unclear, ask before testing. A system is not in scope merely because it links to Uptime Basics or uses a StackResolve service.
2. Research guidelines
- Use only accounts and data you own or are expressly authorized to test.
- Make the minimum requests needed to demonstrate the issue and stop after confirmation.
- Avoid accessing, changing, retaining, or transmitting another person's information.
- Do not create persistence, pivot to another tenant, or download unnecessary records.
- Protect report details and give us a reasonable opportunity to investigate and remediate before any public disclosure.
- Comply with law and this policy. Ask for written approval before any test that might create material load or risk.
3. Prohibited activity
The following are not authorized:
- Denial-of-service, load, stress, volumetric, queue-flooding, SMS-flooding, or resource-exhaustion tests.
- Social engineering, phishing, credential stuffing, password spraying, MFA fatigue, spam, or contacting customers or personnel.
- Physical testing, office access, device theft, or testing home or personal networks.
- Malware, ransomware, destructive payloads, persistence, data deletion, or deliberate service interruption.
- Automated scanning that ignores rate limits, robots controls, access restrictions, or requests to stop.
- Testing monitored targets, third-party integrations, billing providers, identity providers, cloud providers, DNS providers, or email and SMS providers.
- Extortion, demands for payment, threats of disclosure, or trading vulnerability or customer data.
4. What to include
Send one clear report to security@uptimebasics.com. Include the asset and path, vulnerability type, prerequisites, step-by-step reproduction, demonstrated impact, time of testing, source addresses if useful for log review, and a safe proof of concept. Redact secrets and unrelated personal information.
Tell us immediately if you unexpectedly accessed customer data, credentials, payment information, or the ability to disrupt the Service. Do not retain or share it.
5. Our response
We aim to acknowledge a complete report within five business days, provide a status update within ten business days, and communicate material remediation progress when reasonably possible. These are targets, not guarantees. Severity, complexity, provider dependencies, duplicate reports, and incomplete information can affect timing.
We may ask for clarification or request that testing stop. You must comply with a reasonable request to stop or modify testing.
6. Good-faith safe harbour
When research is conducted in good faith, stays within this policy, avoids privacy and availability harm, and is promptly reported, StackResolve will not initiate legal action against you solely for that research. If a third party initiates action, we may confirm that your research complied with this policy where we can do so lawfully.
This statement does not authorize violations of law, waive third-party rights, bind law enforcement or other organizations, or protect activity outside this policy. If you are uncertain, request written permission before continuing.
7. Recognition and rewards
StackResolve does not currently operate a bug-bounty or guaranteed public-recognition program. Do not incur costs or expect payment without a separate written agreement made before the work. We may choose to thank a researcher with permission after remediation, but this is discretionary.
