Vulnerability Disclosure Policy

Introduction
Alida Inc ("Alida," "we," "us," or "our") welcomes reports from security researchers, customers, and the general public who incidentally discover security issues in our products and services. If, in the course of using our products or services, you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issue in any of our assets, we want to hear from you. This policy explains how to report an issue to us, what we ask of you, and what you can expect from us. Alida does not operate a bug bounty program. No monetary rewards, bounties, or other compensation are offered for reports submitted under this policy. You are welcome to submit a report anonymously; however, if we are unable to identify or contact you, we may not be able to update you on its status, ask follow-up questions needed to validate it, or credit your contribution.


What We Accept Reports About
We accept reports concerning any digital assets owned, operated, or maintained by Alida Inc, including our public-facing websites and products and mobile applications.


Reports We Do Not Accept
The following finding types are excluded and will be closed without action:

  • Issues in assets or equipment not owned or controlled by Alida, including third-party services hosted on Alida subdomains (report these to the applicable vendor)

  • Issues affecting the Careers Page (www.alida.com/explorecareers)

  • Missing HTTP security headers

  • Clickjacking

  • SSL/TLS cipher configuration

  • Self-XSS

  • Missing SPF/DKIM/DMARC records

  • Output of automated scanners without a working proof of concept

  • Username, email, or account enumeration on login, signup, or password reset flows

  • Rate-limiting, brute-force, or credential-stuffing observations without demonstrated impact

  • Open redirects without demonstrable security impact

  • Login/logout CSRF and CSRF on non-sensitive actions

  • Presence of known-vulnerable libraries without a demonstrated exploit against an Alida asset

  • Issues in sandbox, demo, or staging environments

  • Any vulnerability obtained through compromise of a customer or employee account

Reporting a finding described in this section is not itself a violation of this policy. Such reports will be reviewed and closed without further action, and — provided the reporter's conduct in discovering and reporting the issue otherwise complied with this policy — will not affect the reporter's standing under the Safe Harbor below.

We also do not accept reports derived from social engineering or phishing of Alida employees, contractors, vendors, or service providers; physical intrusion; sending unsolicited bulk or unauthorized messages; or denial-of-service, volumetric, or resource-exhaustion activity. These activities are prohibited and fall outside the Safe Harbor below.

Issues discovered or suspected in systems outside Alida's control should be reported to the appropriate vendor or applicable authority.


Our Commitments

When you report an issue to us in accordance with this policy, you can expect us to:

  • Acknowledge and respond to your report promptly, and work with you to understand and validate it;

  • Strive to keep you informed about the progress of the issue as it is processed;

  • Work to remediate confirmed issues in a timely manner, within our operational constraints;

  • Not disclose your identity to any third party without your consent, except as required by law or legal process; and

  • Extend the Safe Harbor described below to good-faith reports made under this policy.


Our Expectations

When reporting an issue to us in good faith, we ask that you:

  • Follow this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail;

  • Report the issue promptly after discovering it;

  • Avoid violating the privacy of others, disrupting our systems, destroying data, or harming the experience of our users;

  • Use only the Official Channels to discuss the issue with us;

  • Give us a reasonable amount of time (at least 90 days from the initial report) to investigate and remediate the issue before disclosing it publicly, and coordinate with us in advance on the timing and content of any public disclosure; we will not unreasonably withhold agreement to a disclosure timeline;

  • If an issue provides unintended access to data: limit any access to the minimum required to identify and report the issue; do not retain, copy, share, or further use that data; and stop and submit a report immediately if you encounter any user data, such as personally identifiable information (PII), personal health information (PHI), payment card data, or proprietary information; and

  • Do not engage in extortion, or condition disclosure of an issue on payment or other consideration.


Official Channels

Please report security issues through Alida's vulnerability submission form below. Submitting through the form routes your report directly into our security team's validation and tracking workflow, and lets you follow its status after you submit. The more detail you provide, the easier it will be for us to validate and fix the issue.
If you're unable to use the form, you can also email your report to security@alida.com.

If your report includes sensitive information (such as credentials, personal data, or proprietary information), please flag this clearly and limit what you include to the minimum necessary to demonstrate the issue.

Personal information submitted as part of a report will be handled in accordance with Alida's Privacy Policy.


Safe Harbor

This policy exists to provide a reporting channel for vulnerabilities discovered incidentally. Alida does not operate a public bug bounty program and does not authorize or invite active security testing, scanning, probing, or research against our systems.

This restriction does not apply to security testing, scanning, or research that has been expressly sanctioned by Alida in writing, such as contracted penetration tests, customer-authorized assessments of their own tenant, or other engagements conducted under a separate agreement with Alida. Activities conducted under such an agreement are governed by the terms of that agreement rather than this policy.

For individuals who, in the course of normal use of our products or services, incidentally discover a vulnerability and report it to us in good faith in accordance with this policy, Alida will not pursue or support legal action against the reporter for the act of discovery and reporting, including where identifying the issue involved limited access to data, provided that access was the minimum necessary to identify and report the issue and the reporter did not retain, share, or further use that data. Alida considers conduct that complies with this policy to be authorized, and will not initiate or support a claim against the reporter under the Computer Fraud and Abuse Act (18 U.S.C. § 1030), the Digital Millennium Copyright Act (17 U.S.C. § 1201), analogous state computer-crime statutes, or Alida's Terms of Service or Acceptable Use Policy, to the extent any such claim arises solely from conduct described in this policy. Alida will not refer a good-faith report made in compliance with this policy to law enforcement on its own initiative. If a third party, including law enforcement, initiates legal action against a reporter for conduct that Alida believes complied with this policy, Alida will take reasonable steps to make clear that the reporter's conduct was authorized.

This limited assurance does not apply to, and Alida expressly reserves all rights with respect to:

  • Active security testing, scanning, probing, or exploitation of our systems;

  • Access to, modification of, or exfiltration of customer or user data beyond the minimum necessary to identify and report a discovered issue;

  • Any activity that disrupts or degrades our services or the experience of our users;

  • Extortion, or conditioning disclosure of an issue on payment or other consideration; and

  • Any conduct that violates applicable law, our Terms of Service, or our Acceptable Use Policy beyond what is strictly necessary to report a discovered issue.

Provided your conduct complies with this policy, Alida will not suspend or terminate your account, or restrict your access to our products or services, solely because you submitted a good-faith report under this policy.

You are expected to comply with all applicable laws. Nothing in this policy grants authorization to access systems or data you are not otherwise authorized to access. This assurance applies only to claims under Alida's control and does not bind independent third parties.


General

Alida may update this policy from time to time. The version of this policy in effect at the time you submit a report will govern the commitments and assurances described in it. This policy is a statement of Alida's practices and does not create a contract or any contractual right, and does not guarantee any particular action or outcome. 

Alida is a Community Research platform that helps the world's biggest brands create highly engaged research communities to gather feedback that fuels better customer experiences and product innovation.