Responsible Disclosure Policy | Legal Hub

Responsible Disclosure Policy

Overview

At Carta we are committed to keeping our customers' data secure and private. We take security seriously and to demonstrate that security is a priority to us we ensure that our Responsible Disclosure Policy allows the independent security researchers an opportunity to engage with us and notify us of potential security threats impacting the safety of our customers' data. If you believe you have discovered a potential vulnerability that affects our services, please, let us know.

For any activity you conduct in accordance with the Responsible Disclosure Policy guidelines below, Carta will not take legal actions against you.

General Policy Guidelines

Reporting Guidelines

Do provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Please, fill out the form at the bottom of the page so we can intake and review your submission.

We will investigate any details you provide and respond as soon as possible, usually within three business days, and will keep you reasonably informed of the status of any validated vulnerability that you report through this program.

Submission form

All fields are required unless marked optional.

Summary title

Help us get an idea of what this vulnerability is about.

Submission title

Technical severity

The Vulnerability Rating Taxonomy is the baseline guide used for classifying technical severity.

VRT Category

Select or search for a vulnerability type

VRT Subcategory (optional)

VRT Variant (optional)

Vulnerability details

URL / Location of vulnerability (optional) For example: https://secure.server.com/some/path/file.php

Description

Describe the vulnerability and its impact.

Provide a proof of concept or replication steps.

Maximum 25,000 characters.

Write in Markdown Preview Markdown

Embed images by dragging & dropping, selecting, or pasting them. Markdown supported

Attachments (optional)

Attach proof-of-concept scripts, screenshots, screen recordings, etc.

Add attachments

You can attach up to 20 files. Please keep individual upload size under 400MiB.

You can embed attachments (.jpg/.gif/.png, smaller than 5MB) into the Markdown fields. You can copy the embed code using the ‘Copy as Markdown’ button.

Email

By providing your email address you can claim your submission on bugcrowd.com.

Note: Submissions through this form are welcome. However, if you have been removed from the Bugcrowd platform or this customer’s engagements by the Platform Behavior Standards team:

This form is intended solely for anonymous ethical disclosure and cannot be used to bypass removals.

Researcher email (optional)

Confirmation

Confirm your submission is accurate and adheres to Bugcrowd’s terms & conditions.

I agree to Bugcrowd’s terms & conditions as well as any additional rules and instructions provided by the organization hosting this program.

Report vulnerability.