Vulnerability Disclosure Policy
Last updated: June 3, 2026
1. Introduction
1.1 This Policy
This Vulnerability Disclosure Policy (this "Policy") describes how good-faith security researchers may report suspected security vulnerabilities affecting Altus systems.
1.2 Purpose
Altus welcomes responsible reports of security vulnerabilities that may affect the confidentiality, integrity, or availability of the Services.
This Policy sets out:
(a) the systems and activities that are in scope;
(b) how to submit a vulnerability report;
(c) the conduct expected from security researchers;
(d) the safe-harbor protections we may provide; and
(e) the limitations that apply to any testing or disclosure.
1.3 Capitalized Terms
Capitalized terms not defined in this Policy have the meanings assigned to them in the Altus Terms of Service.
2. Scope
2.1 In-Scope Systems
The following systems are in scope only to the extent they are operated by or on behalf of the Company:
(a) the Altus website;
(b) the Altus application;
(c) public-facing APIs operated by or on behalf of the Company; and
(d) any other system that we expressly identify in writing as in scope.
2.2 Out-of-Scope Systems and Activities
The following are out of scope:
(a) systems operated by the Broker, the Clearing Firm, or other third-party partners;
(b) third-party services, vendors, infrastructure, libraries, applications, or platforms not controlled by us;
(c) social engineering, phishing, spam, or attacks against employees, users, contractors, support teams, vendors, or partners;
(d) physical attacks or attempts to access offices, devices, facilities, or equipment;
(e) denial-of-service, stress, load, or resource-exhaustion testing;
(f) automated scanner findings without demonstrated exploitable impact;
(g) clickjacking or missing security headers without demonstrated security impact;
(h) rate-limit issues without demonstrated security impact;
(i) reports based solely on outdated software versions without a practical exploit path;
(j) issues requiring unlikely user interaction or already-compromised user devices; and
(k) any activity that violates applicable law or causes harm to users, systems, data, or third parties.
3. How to Report
3.1 Reporting Channel
Please report suspected vulnerabilities to:
security@altus.trade
3.2 Report Contents
Your report should include, where available:
(a) a clear description of the suspected vulnerability;
(b) the affected domain, endpoint, API, application screen, feature, or component;
(c) detailed reproduction steps;
(d) proof-of-concept details, screenshots, logs, or videos where helpful;
(e) the potential security impact;
(f) any accounts, IP addresses, user agents, timestamps, or test identifiers used during testing; and
(g) your contact information.
3.3 Coordinated Disclosure
You must not publicly disclose, publish, share, sell, or otherwise disseminate any suspected vulnerability, exploit, proof of concept, or related information unless and until:
(a) we have investigated and remediated the issue;
(b) we have confirmed that disclosure may proceed; or
(c) we have otherwise agreed with you on a coordinated disclosure timeline.
4. Safe Harbor
4.1 Safe-Harbor Commitment
If you make a good-faith effort to comply with this Policy, we will:
(a) treat your research as authorized to the extent it is conducted strictly within the scope of this Policy;
(b) not pursue or support legal action against you for accessing, testing, or reporting vulnerabilities in accordance with this Policy; and
(c) work with you in good faith to understand, validate, and remediate the reported issue.
4.2 Limitations
This safe harbor applies only to systems controlled by us and only to activity that complies with this Policy.
This safe harbor does not apply to:
(a) systems operated by the Broker, the Clearing Firm, or other third parties;
(b) activity outside the scope of this Policy;
(c) activity that violates applicable law;
(d) activity that causes harm, disruption, degradation, unauthorized access, data loss, or privacy violations; or
(e) activity conducted after we ask you to stop testing.
4.3 Excluded Conduct
Safe harbor does not apply if you:
(a) access, modify, destroy, delete, encrypt, copy, transfer, disclose, or exfiltrate data beyond the minimum necessary to demonstrate the vulnerability;
(b) access user data, personal data, private keys, credentials, financial data, trading data, or confidential information beyond what is strictly necessary;
(c) degrade, interrupt, disrupt, impair, or attempt to impair the Services or any related system;
(d) conduct denial-of-service, stress, load, or resource-exhaustion testing;
(e) use social engineering, phishing, spam, credential theft, or physical attacks;
(f) attempt to extort, threaten, coerce, or pressure us, our users, employees, contractors, vendors, partners, the Broker, the Clearing Firm, or any third party;
(g) publicly disclose an issue without coordinated disclosure approval;
(h) test systems operated by the Broker, the Clearing Firm, or other third parties without their authorization; or
(i) otherwise violate this Policy or applicable law.
5. Researcher Expectations
5.1 Responsible Conduct
You agree to:
(a) act in good faith;
(b) test only in-scope systems;
(c) avoid privacy violations, data destruction, service disruption, and harm to users or third parties;
(d) use only your own accounts or accounts you are expressly authorized to test;
(e) access only the minimum data necessary to demonstrate the vulnerability;
(f) stop testing and notify us immediately if you encounter user data, credentials, private keys, confidential information, financial data, or trading data;
(g) not store, copy, transfer, disclose, sell, or use any user data or confidential information;
(h) give us reasonable time to investigate, validate, and remediate the issue before any public disclosure;
(i) coordinate any public disclosure with us; and
(j) comply with all applicable laws.
5.2 Data Handling
If you inadvertently access any user data, personal data, credentials, private keys, confidential information, financial data, or trading data, you must:
(a) stop testing immediately;
(b) notify us promptly;
(c) not copy, retain, share, disclose, or use the data;
(d) delete any locally stored copies where safe and legally permitted; and
(e) follow our reasonable instructions regarding containment and remediation.
6. Rewards
6.1 No Fixed Bounty
The Company does not operate a fixed-amount bug bounty program and does not commit to any specific payment, reward, or compensation.
6.2 Discretionary Rewards
At our sole discretion, we may provide a discretionary reward based on factors including:
(a) severity;
(b) impact;
(c) novelty;
(d) exploitability;
(e) affected scope;
(f) quality of the report;
(g) reproducibility; and
(h) your compliance with this Policy.
6.3 Reward Eligibility
Eligibility for any reward requires that:
(a) the report concerns a valid and previously unknown vulnerability;
(b) the vulnerability affects an in-scope system;
(c) you fully comply with this Policy;
(d) you do not publicly disclose the issue without our approval; and
(e) you are not a Restricted Person, located in a Restricted Jurisdiction, subject to sanctions, or otherwise prohibited from receiving payment under applicable law.
6.4 No Obligation
Any decision to provide, deny, modify, or withhold a reward is made at our sole discretion.
7. No Other Rights
7.1 No Relationship Created
Submitting a report does not create any employment, contractor, partnership, agency, fiduciary, joint venture, or other relationship with the Company.
7.2 License to Submitted Materials
You grant the Company a perpetual, worldwide, royalty-free, irrevocable license to use, reproduce, modify, disclose, and otherwise process any materials you submit as reasonably necessary to:
(a) investigate the report;
(b) validate the vulnerability;
(c) remediate the issue;
(d) document security findings;
(e) improve the Services; and
(f) comply with legal, regulatory, security, or operational requirements.
7.3 No Confidentiality Obligation
Unless separately agreed in writing, submitting a report does not impose any confidentiality obligation on the Company with respect to the submitted materials.
8. Changes to This Policy
8.1 Updates
We may amend, supplement, or replace this Policy from time to time by posting the updated version with a new "Last Updated" date.
8.2 Effect of Updates
Your continued testing, reporting, or interaction with us under this Policy after an updated version becomes effective constitutes acceptance of the updated Policy.
9. Contact
For vulnerability reports and security-related inquiries, contact:
security@altus.trade
© 2026 Altus · info@altus.trade
