Global B2B Group welcomes reports from security researchers who identify vulnerabilities in the Platform. This policy sets out a safe-harbour framework for good-faith research.
1. Scope
- Web applications hosted on globalb2bgroup.com and its sub-domains.
- Portfolio-brand sites operated by Global B2B Group.
- Public APIs documented by Global B2B Group.
2. Out of scope
- Denial of service, volumetric or resource-exhaustion attacks.
- Physical, social-engineering or phishing attacks against staff or users.
- Third-party services not operated by Global B2B Group.
- Automated scanning that generates high traffic without prior authorisation.
3. Ground rules
- Do not access, modify, delete or exfiltrate personal or confidential data.
- Use test accounts you create; do not attempt to access other users' accounts.
- Report vulnerabilities promptly and do not publicly disclose before coordination.
- Give Global B2B Group a reasonable time to remediate (typically 90 days).
- Do not violate any law.
4. Safe harbour
Global B2B Group will not pursue civil or administrative action against researchers who act in good faith within the scope and rules of this policy. Where third-party consent is needed, we will attempt to obtain it. This safe harbour does not authorise activity that violates applicable law.
5. How to report
Email security@globalb2bgroup.com with: a clear description, reproduction steps, proof-of-concept if any, impact assessment and your contact details. PGP is available on request.
6. Response
We aim to acknowledge reports within five business days, provide a triage decision within ten business days and keep researchers informed until remediation.
7. Recognition
Global B2B Group does not currently operate a paid bug-bounty programme but will credit researchers publicly on request where appropriate.
