Vulnerability Disclosure Policy
Vulnerability Disclosure Policy
Tucows is dedicated to keeping our company and the Internet community safe. No technology is perfect and we value the contributions of security researchers and members of the broader community who help us maintain high standards of cybersecurity. If you believe you’ve found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.
What is a Vulnerability Disclosure Program?
A Vulnerability Disclosure Program (VDP) is the "see it, say it, sorted" of the Internet. We welcome reports from anyone—whether you're a customer, an independent researcher, or someone who simply stumbled upon something unusual. If you’ve discovered a potential security issue affecting Tucows products or services, we want to hear from you.
If you are a professional security researcher, we also invite you to participate in our bug bounty program on HackerOne.
Who can participate?
● Anyone on the Internet can participate.
Things to consider including are:
● A thorough documentation of your findings, including steps to reproduce the flaw.
● Reports with complete vulnerability details—including screenshots or video—are essential for a quick response.
We ask that you:
● Do not disclose the vulnerability publicly before we have had a chance to investigate and address the issue.
● Avoid accessing, modifying, or deleting data that does not belong to you.
● Act in good faith and in accordance with applicable laws.
● Do not use this VDP to make general product or feature requests.
● All security issues and vulnerability reports should be submitted to our Security Team via HackerOne.
Our Commitments
❖ We will acknowledge your report promptly.
❖ We will investigate the issue thoroughly and may provide you updates.
❖ We will resolve confirmed vulnerabilities as quickly as possible.
❖ We are dedicated to offering safe harbour to researchers and disclosures made in good faith.
Safe Harbor
We are committed to engaging with the security community in a constructive, respectful, and transparent manner. Activities conducted in accordance with this policy will be considered authorized and we will not initiate legal action against researchers who follow these guidelines in good faith.
If you have any questions about our Vulnerability Disclosure Program, feel free to reach out to us at bug-reports@tucows.com.