Legal
Vulnerability Disclosure Policy
Effective 15 September 2026
Responsible disclosure
We appreciate your help securing ServiceProof. Cimbrian, Inc. acknowledges the importance of privacy, security and community outreach, and we are committed to verifying and addressing security issues through a coordinated and constructive approach designed to give the greatest protection to the people who use this software.
Whether you are a ServiceProof customer, a technician using the app, a vendor or simply a security enthusiast, you are an important part of this process. Accordingly, we encourage responsible reporting of any confirmed or potential vulnerability found in our app, our websites or our services.
Reporting security or privacy issues
If you believe you have found a vulnerability in ServiceProof or in a ServiceProof integration, please share the details of your discovery privately — including the steps to reproduce it — with us at security@svcproof.com. If the matter is urgent you can also call 717-808-0988.
When properly notified of a legitimate issue, we will do our best to acknowledge your report, assign resources to investigate and confirm it, address the problem as appropriate for the assessed risk, and notify you when it is resolved. We ask that you keep communications regarding the vulnerability confidential until it has been addressed. Please note that monetary rewards are not guaranteed for validated submissions.
Testing for security vulnerabilities
Examples of encouraged submission types include:
- OWASP Top 10
- Authorization and authentication issues
- Information disclosure
- Business logic and process vulnerabilities
We prohibit assessments involving automated scanning tools, and any of the following:
- Social engineering
- Physical security attacks
- Tests against our customers, partners or any other third party
- Actions that may degrade the performance or availability of our services, such as denial of service and brute force
- Attempting to access or modify information that does not belong to you
- Actions that may violate laws or constitute a breach of any contract
- Compounding or creating new vulnerabilities or weaknesses
- Anything that helps to maintain a foothold or evade detection
A contractor’s ESC database holds their customers’ names, addresses and payment history. Please treat anything you encounter during testing as if it were your own customers’ data, and tell us rather than demonstrating at scale.