1. OVERVIEW
FourKites maintains a responsible disclosure process for legitimate security researchers to report verified vulnerabilities in our systems. This policy applies exclusively to security issues affecting https://app.fourkites.com and FourKites-owned infrastructure.
2. ELIGIBILITY
To participate in our Responsible Disclosure Program, you must meet all of the following requirements:
- You must be at least 18 years old or have reached the age of majority in your country of citizenship and primary residence
- You must be participating as an individual security researcher. You cannot participate if you are:
- A current FourKites employee or contractor
- An employee of a company that has a business relationship with FourKites
- A family member of a FourKites employee or contractor
- You must not be:
- Affiliated with any entity on a United States sanctions list
- A resident of any country subject to United States sanctions
- You must be legally permitted to receive compensation for security research services under the laws applicable to you
By participating in this program, you confirm that you meet all eligibility requirements listed above. FourKites reserves the right to verify eligibility and may disqualify participants who do not meet these requirements.
3. REPORTING REQUIREMENTS
Security vulnerabilities must be reported to soc@fourkites.com with comprehensive technical documentation including:
- Detailed vulnerability description and classification
- Complete reproduction steps with proof-of-concept
- Impact assessment and remediation recommendations
- Researcher contact information
Subject: Bug Bounty: <Vulnerability Type> - <Participant's Full Name>
Email Body: Vulnerability Information:
- Name of Vulnerability:
- Vulnerability type:
- Description:
- Vulnerable Instances:
- Steps to Reproduce:
- Proof of Concept:
- Impact:
- Recommendation:
Bounty Hunter Details:
- Full Name:
- Email Address:
- Mobile Number:
- Any Publicly Identifiable Profile:
4. PROGRAM RULES
- Reports must demonstrate genuine security vulnerabilities with clear reproduction steps
- Only the first valid submission of duplicate vulnerabilities will be considered
- Participants must maintain strict confidentiality throughout the program
- Testing must not disrupt services, access unauthorized data, or violate user privacy
- Social engineering, automated scanning tools, and bulk submissions are prohibited
- Researchers who receive a compensation will be required to execute a Non-Disclosure Agreement before any reward is issued
5. RESPONSE PROCESS
FourKites aims to acknowledge valid reports within 5 business days and provide updates every 10 business days until resolution. Resolution timelines vary based on severity and complexity.
6. RECOGNITION
FourKites may, at its sole discretion, provide recognition for verified, high-quality vulnerability reports that meet all program requirements. If multiple vulnerabilities stem from a single root cause, they will be treated as one issue for reward purposes.
7. SCOPE LIMITATIONS
This program does not cover:
- Third-party services or applications
- Social engineering attacks (including phishing, vishing, or smishing) targeting FourKites employees, contractors, or customer
- Physical security issues
- Industry-standard configuration recommendations
- Issues requiring user interaction or physical device access
- Known vulnerabilities or recently patched issues (within 30 days)
8. LEGAL FRAMEWORK
FourKites will not initiate legal proceedings or suspend access to its services based solely on good faith security research conducted within these guidelines, subject to applicable legal obligations. Violation of program rules will result in immediate termination of engagement. This policy is governed by United States law.
9. CONFIDENTIALITY
By participating in this program, researchers agree to:
- Maintain strict confidentiality of any vulnerabilities discovered and all information obtained during security research activities.
- Not disclose any findings publicly or to third parties without FourKites' prior written consent. After remediation, researchers may request coordinated disclosure, subject to FourKites' sole discretion.
Breach of these confidentiality commitments may result in disqualification from the program and potential legal action.
10. CONTACT
Questions regarding this policy should be directed to soc@fourkites.com.