Uptime Basics logo
HomeServicesPricingGuidesContact
Vulnerability Disclosure

Help us protect Uptime Basics

Good-faith security research can make the Service safer. This policy defines authorized scope, safe testing, reporting expectations, and activities that require advance written permission.

Effective and last updated: August 23, 2026
Report confidentially

Email security@uptimebasics.com with the affected asset, impact, reproduction steps, and any supporting evidence. Do not include unrelated personal data or working credentials.

Contents1. Scope2. Research guidelines3. Prohibited activity4. Reporting5. Our response6. Safe harbour7. Recognition

1. In-scope systems

This policy applies to publicly accessible systems operated by StackResolve at uptimebasics.com, its application and API subdomains, and stackresolvehq.com. It does not authorize testing of customer-monitored websites, customer custom domains, status pages not operated by StackResolve, provider infrastructure, employee or customer devices, or any third-party service.

If ownership is unclear, ask before testing. A system is not in scope merely because it links to Uptime Basics or uses a StackResolve service.

2. Research guidelines

  • Use only accounts and data you own or are expressly authorized to test.
  • Make the minimum requests needed to demonstrate the issue and stop after confirmation.
  • Avoid accessing, changing, retaining, or transmitting another person's information.
  • Do not create persistence, pivot to another tenant, or download unnecessary records.
  • Protect report details and give us a reasonable opportunity to investigate and remediate before any public disclosure.
  • Comply with law and this policy. Ask for written approval before any test that might create material load or risk.

3. Prohibited activity

The following are not authorized:

  • Denial-of-service, load, stress, volumetric, queue-flooding, SMS-flooding, or resource-exhaustion tests.
  • Social engineering, phishing, credential stuffing, password spraying, MFA fatigue, spam, or contacting customers or personnel.
  • Physical testing, office access, device theft, or testing home or personal networks.
  • Malware, ransomware, destructive payloads, persistence, data deletion, or deliberate service interruption.
  • Automated scanning that ignores rate limits, robots controls, access restrictions, or requests to stop.
  • Testing monitored targets, third-party integrations, billing providers, identity providers, cloud providers, DNS providers, or email and SMS providers.
  • Extortion, demands for payment, threats of disclosure, or trading vulnerability or customer data.

4. What to include

Send one clear report to security@uptimebasics.com. Include the asset and path, vulnerability type, prerequisites, step-by-step reproduction, demonstrated impact, time of testing, source addresses if useful for log review, and a safe proof of concept. Redact secrets and unrelated personal information.

Tell us immediately if you unexpectedly accessed customer data, credentials, payment information, or the ability to disrupt the Service. Do not retain or share it.

5. Our response

We aim to acknowledge a complete report within five business days, provide a status update within ten business days, and communicate material remediation progress when reasonably possible. These are targets, not guarantees. Severity, complexity, provider dependencies, duplicate reports, and incomplete information can affect timing.

We may ask for clarification or request that testing stop. You must comply with a reasonable request to stop or modify testing.

6. Good-faith safe harbour

When research is conducted in good faith, stays within this policy, avoids privacy and availability harm, and is promptly reported, StackResolve will not initiate legal action against you solely for that research. If a third party initiates action, we may confirm that your research complied with this policy where we can do so lawfully.

This statement does not authorize violations of law, waive third-party rights, bind law enforcement or other organizations, or protect activity outside this policy. If you are uncertain, request written permission before continuing.

7. Recognition and rewards

StackResolve does not currently operate a bug-bounty or guaranteed public-recognition program. Do not incur costs or expect payment without a separate written agreement made before the work. We may choose to thank a researcher with permission after remediation, but this is discretionary.

Uptime Basics logo
Reliable monitoring for small businesses, agencies, and founders that want clear visibility without enterprise overhead.
Made in Canada.

Product

ServicesGuidesPublic Status PagesPricing

Company

ContactSecurityAccessibility

Legal

Legal & TrustPrivacy PolicyTerms of ServiceSub-processors