Security

Responsible Disclosure Policy

If you believe you have found a security vulnerability in a system operated by Apollo Technology Services LLC, we want to hear from you — and we will work with you in good faith.

Company: Apollo Technology Services LLC
Policy: Coordinated vulnerability disclosure
Machine-readable: /.well-known/security.txt

1. Scope

This policy applies to infrastructure and services owned and operated by Apollo Technology Services LLC, including domains and applications that publish this policy or a reference to it.

It does not authorise testing of third-party systems, of our clients' systems without their own written permission, or of any service where we are merely a user. If you are unsure whether a target is in scope, ask us before testing.

2. How to report

Email your report to admin@apollotechnologyservices.app with the subject line Security vulnerability report. Please include:

  • The affected system, URL or component;
  • A clear description of the issue and its potential impact;
  • Reproduction steps sufficient for us to confirm it;
  • Any proof-of-concept material, redacted where it contains real user data;
  • How you would like to be credited, if at all.

Please do not include unnecessary personal data, and do not access, modify, download or retain data that is not yours.

3. What we commit to

  • We will acknowledge your report within 3 business days.
  • We will give you an initial assessment and expected timeline within 10 business days.
  • We will keep you informed of meaningful progress toward a fix.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • We will credit you publicly (with your consent) once the issue is resolved.

4. What we ask of you

Act in good faith, avoid privacy violations, avoid service degradation, and give us a reasonable opportunity to remediate before public disclosure.
  • Do not access, alter or exfiltrate data belonging to others.
  • Do not perform denial-of-service, load or resource-exhaustion testing.
  • Do not use social engineering against our staff, clients or suppliers.
  • Do not run automated scanners at a volume that degrades our services.
  • Give us 90 days to remediate before disclosing publicly, or a shorter period if we agree.

5. Out of scope

  • Reports generated solely by automated scanners without demonstrated impact.
  • Missing security headers or best-practice observations with no exploitable consequence.
  • Social engineering, phishing simulations or physical attacks against our staff.
  • Denial-of-service and volumetric findings.
  • Vulnerabilities in third-party software with no demonstrable impact on our systems.

6. Bounties

We do not operate a paid bug bounty programme at this time. We are grateful for reports made under this policy and will credit researchers who wish to be named.

7. Contact

Security reports: admin@apollotechnologyservices.app
General enquiries: contact page