Security

Vulnerability Disclosure Program

Breach Point values the work of security researchers who help keep Insight Recon and our customers secure. If you've found a vulnerability, we want to hear from you.

Effective Date: January 1, 2026 Last Updated: January 1, 2026 Submit to: [email protected]
This Vulnerability Disclosure Program applies only to the assets and software listed in the In Scope section below. By participating, you agree to follow this policy and avoid any activity that could harm Breach Point, Insight Recon, our customers, or third parties.
Section 01

Overview

Breach Point values the work of security researchers who help keep Insight Recon and our customers secure. If you believe you have discovered a security vulnerability affecting Insight Recon, we encourage you to report it responsibly so we can investigate and address the issue promptly.

Section 02

Responsible Disclosure Guidelines

Report suspected vulnerabilities as soon as reasonably possible after discovery.
Do not publicly disclose or share vulnerability details with third parties without written authorization from Breach Point.
Only test systems, accounts, tenants, software installations, and data that you own or have explicit permission to test.
Do not access, modify, download, retain, or destroy customer data.
Avoid testing that could degrade, disrupt, or damage any service, system, customer environment, or third-party resource.
!If you accidentally access sensitive information or cause unintended impact, stop testing immediately and notify us.
Section 03

Program Rules

Submit one vulnerability per report unless multiple issues are required to demonstrate impact.
Include clear reproduction steps, affected assets, proof of concept details, and a description of the security impact.
Reports without enough detail to reproduce the issue may not be triaged.
Duplicate reports may be closed if the issue was previously reported or internally identified.
Multiple findings caused by the same underlying issue may be treated as a single report.
Automated testing must be reasonable and must not create excessive traffic, service degradation, or operational impact.
Section 04

In Scope Assets

In ScopeAuthorized for security testing
*.insightrecon.com
Insight Recon software distributed directly by Breach Point
Official Insight Recon APIs
Official Insight Recon cloud storage and cloud-connected services
Insight Recon installation packages and update mechanisms distributed directly by Breach Point
Important: Any application, domain, endpoint, system, service, API, or infrastructure not expressly listed above is out of scope.
Section 05

Explicitly Out of Scope Assets

Out of ScopeDo not test these assets
Customer-owned Insight Recon deployments
Customer Active Directory environments
Customer networks, endpoints, cloud tenants, or internal systems
Third-party services, integrations, vendors, or partner systems
Employee devices or personal accounts
Development, staging, or internal systems not explicitly listed as in scope
Contact forms, support forms, lead forms, demo request forms, or feedback forms
Physical offices, facilities, or personnel
Section 06

Out of Scope Vulnerabilities

The following findings are generally considered out of scope unless you can demonstrate meaningful, exploitable security impact:

Software version disclosure, banner grabbing, descriptive errors, stack traces, or public files such as robots.txt
Missing or incomplete security headers without demonstrated exploitability
Missing SPF, DKIM, DMARC, or other email security best practices
Missing Secure or HttpOnly cookie flags without demonstrated security impact
Clickjacking on pages without sensitive actions
Tabnabbing
Open redirects without additional security impact
CSV injection without demonstrated impact
Self-XSS or issues requiring unrealistic user interaction
Text injection or content spoofing without meaningful exploitability
Username enumeration without meaningful security impact
Weak CAPTCHA or CAPTCHA bypass findings
Rate limiting, brute force, or account lockout recommendations on non-sensitive endpoints
Vulnerable third-party libraries without a working proof of concept affecting Insight Recon
Dependency scanner results, SBOM findings, or package version observations without demonstrated exploitability
Public CVEs with official patches released less than 30 days prior to submission
Findings requiring physical access, local machine compromise, man-in-the-middle positioning, or unsupported software versions
Section 07

Prohibited Testing

The following activities are not permitted under any circumstances:

Denial of service or distributed denial of service testing
Resource exhaustion attacks
Excessive automated scanning
Credential stuffing, password spraying, or brute force attacks
Social engineering — phishing, vishing, smishing, impersonation, or pretexting
Malware deployment, ransomware simulation, or destructive payloads
Spam or unsolicited message generation
Accessing, modifying, deleting, or exfiltrating customer data
Pivoting into customer environments or third-party systems
Reverse engineering to bypass licensing, payment, or copy-protection controls
Testing intended to evade Insight Recon licensing restrictions or usage limits
Supply chain attacks against package repositories, build systems, or update infrastructure
Need to go further? If you believe a vulnerability requires prohibited testing to demonstrate impact, contact us at [email protected] before proceeding.
Section 08

Safe Harbor

Good faith protection: Security research conducted in good faith and in accordance with this policy will be considered authorized by Breach Point. We will not pursue legal action against researchers who follow this policy, avoid harm to customers and services, and promptly report discovered vulnerabilities.

If legal action is initiated by a third party related to activity conducted under this policy, Breach Point may take reasonable steps to communicate that your activity was performed in accordance with this program.

We understand that mistakes can happen during responsible testing. If unintended impact occurs, notify us immediately with details about what happened, when it happened, the systems involved, and any steps taken to limit impact.

Safe Harbor Violations: Reckless testing, failure to disclose unintended impact, or activity outside this policy may result in suspension of testing privileges, temporary or permanent blocking of systems or IP addresses, removal from future program participation, or other action where legally appropriate.
Section 09

Submitting a Report

Security reports should be sent to [email protected]. Please include the following in your submission:

Vulnerability title
Affected asset
Steps to reproduce
Proof of concept
Security impact
Suggested remediation, if available

We appreciate the security community's help in keeping Insight Recon, Breach Point, and our customers secure.