1. Good-faith research
AlpineLayer welcomes responsible vulnerability reports. Researchers acting in good faith, minimizing harm and following this policy will not be treated as malicious solely for authorized research described here, to the extent AlpineLayer can make that commitment under applicable law.
2. Allowed testing
- Testing your own account and resources.
- Non-destructive testing of public AlpineLayer applications without accessing another user’s data.
- Proof-of-concept activity limited to what is necessary to show the issue.
3. Prohibited activity
- Accessing, copying, modifying or deleting other users’ data.
- Social engineering employees or customers.
- Physical intrusion, denial-of-service or traffic flooding.
- Persistent access, malware deployment or destructive testing.
- Public disclosure before AlpineLayer has had a reasonable chance to investigate and remediate.
4. Report
Send reports to security@alpinelayer.ch with the asset, issue, reproduction steps, impact and contact information. A PGP key can be added to security.txt later.
5. Response
AlpineLayer will acknowledge credible reports, investigate severity and coordinate remediation where practical. No bug-bounty payment is promised unless a formal program is published.