Responsible Disclosure Policy
UBC PHAS protects information created by us, or given to us, to ensure appropriate confidentiality and integrity. Therefore, the security of our information systems is of paramount importance to us.
If you discover a vulnerability in one of our systems, we would like to know about it so that we can address it as quickly as possible.
Please do the following:
- Email your findings to security@phas.ubc.ca.
- Include enough information for us to reproduce the problem
- Do not take advantage of the vulnerability, for example by downloading more data than is necessary to demonstrate the vulnerability or making changes to the information system
- Do not reveal the vulnerability to others until it has been resolved
UBC PHAS’s Computer Incident Response Team will review your submission. If the vulnerability is valid, mitigation will be performed in accordance with the company’s internal procedures. You will be notified when the problem has been resolved.
We will not take legal action towards those who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy.