Vulnerability Disclosure Policy

Advent Business Company, Inc. — Enablement® platform · Effective 2026-07-13 · Version 1.0

Report a security issue: email security@adventbusiness.com. Machine-readable contact: /.well-known/security.txt.

Our commitment

Advent Business Company, Inc. is committed to the security of the Enablement® platform and the data entrusted to it by our customers. We welcome reports of security vulnerabilities from researchers, customers, and the public, and we will work in good faith to validate, remediate, and acknowledge valid reports.

Scope

In scope: the Enablement® production service at https://enablement.cc and its documented APIs.

Out of scope: third-party services we rely on (report those to their owners); denial-of-service testing; social engineering of Advent staff or customers; physical attacks; and automated scanning that degrades service availability.

How to report

Email security@adventbusiness.com with:

Please report promptly upon discovery and give us a reasonable opportunity to remediate before any public disclosure. Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the vulnerability.

Our response commitments

StageTarget
Acknowledge receiptWithin 3 business days
Initial assessment / triageWithin 10 business days
Status updatesAt least every 15 business days until resolved
Remediation of confirmed high/critical issuesPrioritized per our Vulnerability Detection & Response process

Confirmed vulnerabilities are entered into our tracked remediation process and evaluated using our Potential Agency Impact (PAIN) rating model.

Safe harbor

Advent will not pursue legal action against researchers who act in good faith; comply with this policy; avoid privacy violations, data destruction, and service disruption; and give us reasonable time to remediate before public disclosure. If in doubt about whether an action is authorized, contact us first at security@adventbusiness.com.

Acknowledgments

We publicly thank researchers who responsibly disclose valid vulnerabilities (with their permission). This section will list acknowledged reporters.


Reviewed annually and upon material change. For general support, contact support@adventbusiness.com.