Vulnerability Disclosure Policy
Effective Date: August 1, 2026 | Last Updated: August 1, 2026
1. Introduction
Comet Foundry is a 501(c)(3) nonprofit and student-led organization committed to protecting the security and privacy of our members, partners, and the broader community we serve. We recognize the important role independent security research plays in keeping any internet-facing platform safe, and we welcome reports from researchers who identify vulnerabilities in good faith.
This Vulnerability Disclosure Policy ("Policy") is written in alignment with recognized coordinated vulnerability disclosure standards, including ISO/IEC 29147, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Template, and the U.S. Department of Justice's Framework for a Vulnerability Disclosure Program for Online Systems. It describes the systems and research types covered, how to submit a report to us, and what you can expect in return.
2. Our Operating Context
Comet Foundry operates on nonprofit, volunteer-managed technical resources rather than a dedicated, full-time enterprise security operations team. We hold ourselves to the same good-faith standards described in this Policy as larger, commercially resourced organizations, and we are committed to responding to every valid report; however, our remediation timelines reflect the operational capacity of a student-run nonprofit and may extend beyond those of a commercial enterprise for lower-severity findings.
3. Authorization
If you make a good-faith effort to comply with this Policy during your security research, we will consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and Comet Foundry will not recommend or pursue legal action related to your research, provided you have acted in accordance with this Policy.
Should legal action be initiated by a third party against you for activities conducted in good-faith compliance with this Policy, we will make it known, including in relevant legal proceedings, that your actions were conducted in compliance with this Policy.
4. Scope
This Policy applies to the following:
- The Comet Foundry website, cometfoundry.com, and its subdomains
- The broader Comet Foundry platform, including any systems, applications, and services directly owned and operated by Comet Foundry
Any service not explicitly listed above, such as third-party platforms we integrate with or rely on, is out of scope and outside our authority to authorize testing on. If you are unsure whether a system is in scope, contact us at [email protected] before beginning testing.
If you identify a vulnerability in a third-party system that you believe affects Comet Foundry data or users, please report it to us at [email protected] rather than testing it directly. We will coordinate with the relevant third party on your behalf and keep you informed of the outcome.
5. Out of Scope
The following are outside our authority to authorize testing on directly. If you find an issue here that you believe affects Comet Foundry, report it to us at [email protected] and we will raise it with the relevant party on your behalf.
- Third-party payment processors, donation platforms, and embedded form providers
- Underlying cloud, hosting, DNS, or content-delivery infrastructure providers, at the platform level
- Social engineering, phishing, vishing, or other non-technical attacks directed at Comet Foundry officers, members, or volunteers
- Physical security testing of any kind
6. Guidelines: Authorized Research Conduct
Under this Policy, "research" means activities in which you:
- Notify us immediately upon discovery of a vulnerability, and do not disclose it to any other party
- Make a good-faith effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data
- Only interact with test accounts you own or with explicit permission from the account holder
- Do not exploit a vulnerability beyond the minimal action necessary to demonstrate that it exists
- Cease testing and notify us immediately if you encounter personal data, financial information, or proprietary information belonging to any party, and do not access, retain, or further expose such data
7. Test Methods Not Authorized
The following are not authorized under this Policy and should not be used at any time:
- Network denial-of-service (DoS or DDoS) attacks or any test that impairs access to or damages a system or its data
- Physical testing, such as office access attempts or tailgating
- Social engineering, phishing, or vishing directed at Comet Foundry personnel
- Automated, high-volume scanning that materially degrades platform performance or availability
- Submission of a high volume of low-quality or automatically generated reports
8. How to Submit a Report
Reports may be submitted to [email protected]. We accept reports in English. To help us triage efficiently, please include, where possible:
- A clear description of the vulnerability, including the affected system, page, or endpoint
- The potential impact of the vulnerability, if exploited
- Step-by-step reproduction instructions
- Supporting evidence such as screenshots, logs, or proof-of-concept code, without including any personal or sensitive data of third parties
If you are able to, please encrypt your report to protect its contents in transit.
9. What You Can Expect From Us
| Severity | Target Acknowledgment | Description |
|---|---|---|
| Critical | Within 48 hours | Remote code execution, authentication bypass, or exposure of sensitive personal data |
| High | Within 5 business days | Significant data exposure or privilege escalation with limited scope |
| Medium | Within 10 business days | Issues such as reflected cross-site scripting, CSRF, or misconfigurations with moderate impact |
| Low | Best effort | Minor issues with limited security impact, such as missing headers or verbose error messages |
Upon receipt, we will acknowledge your report, work to validate and reproduce the issue, and keep you informed as we investigate and remediate. We will notify you when the reported vulnerability has been resolved and may ask for your assistance in confirming the fix.
10. Confidentiality
Reports and any related communications are treated as confidential. We will not share details of an unresolved vulnerability with third parties except as necessary to investigate or remediate the issue, or as required by law. We ask that you likewise refrain from public disclosure until we have had a reasonable opportunity to remediate the issue, and that we coordinate on timing before any public disclosure occurs.
11. Recognition
Comet Foundry does not currently operate a paid bug bounty program. Researchers who submit a valid report in good-faith compliance with this Policy will, upon request, receive a signed Comet Foundry Recognition Certificate acknowledging their contribution to the security of our platform, and may be listed in a public acknowledgments record unless they prefer to remain anonymous.
12. Questions
Questions regarding this Policy, or requests for clarification on whether a specific test or system is in scope, may be directed to [email protected] prior to beginning research.
13. Changes to This Policy
Comet Foundry may revise this Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be posted on this page with a revised "Last Updated" date.
14. Contact
Comet Foundry
[email protected]
