Feedback

TRANSPARENCY

Maintaining Responsible Disclosure

We believe that we all benefit when the security process works as designed. It's why we built VMP™ Pass' security strategy around rapid response to reports of bugs or vulnerabilities. In addition to undergoing rigorous, ongoing internal reviews, we also look to the VMP™ Pass community to challenge our technology, offering users various ways they can contribute their input.

Direct communication to the VMP™ Pass security team

Coming Soon: Our dedicated security disclosure program is currently being established. In the meantime, if you have identified a security concern, please reach out through our contact channels.

Customers with a security concern should report it via email to info@vmppass.com where it will be escalated to the threat intelligence team.

When reporting potential issues, we ask that users please try to be as thorough as possible in providing information that will allow the VMP™ Pass team to appropriately recreate their findings. This may include exact steps to reproduce the bug, any links that were clicked on, pages that were visited, URLs, and any affected account email addresses. Please include a code sample and either images or a video recording that clearly demonstrates the exploit.

Report suspicious emails

Did you receive a suspicious email? Do you need to report it to clarify its legitimacy?

Please forward any questionable emails to info@vmppass.com. Our team will take appropriate action from there; we will notify you as to whether the email is legitimate.

bugcrowd

Bug bounty program

Coming Soon: VMP™ Pass will be launching a comprehensive bug bounty program in partnership with leading security research platforms to facilitate responsible disclosure of security issues.

In addition to our own direct responsible disclosure program, VMP™ Pass will participate in a bug bounty program to facilitate the work that security researchers do to find and responsibly disclose qualifying security bugs. We appreciate the important work that the security research community provides and their responsible disclosure of issues.

We will accept reports through BugCrowd for all our products, which includes Password Manager, SSO and MFA solutions.

Response to security concerns

Once a security concern has been submitted and resolved directly or via BugCrowd, our team typically follows these steps:

  1. Take steps to investigate the report and determine its severity.
  2. Contact the reporter directly to acknowledge receipt of the issue and to get more information if needed.
  3. If we are able to replicate the reported issue and determine that it is necessary to take action, we will fix the issue or perform mitigation effort as applicable. While issues are usually fixed quickly, deploying a fix depends on the complexity, severity of the issue, and update-release process.
  4. Once we take the appropriate steps to resolve the issue, we'll close the report.

Note: This is not permission or encouragement to gain unauthorized access to VMP™ Pass applications, download or disclose any proprietary or confidential information (including customer data), disrupt or compromise any VMP™ Pass operations or data, or violate any law.

Trust Center

Your single source for the latest security, privacy, compliance, and system availability information.

Technical white paper

Read about how we built the VMP™ Pass security to ensure that your data is protected throughout.

VMP™ Pass encryption model

Your data is kept secret, even from us. Learn how VMP™ Pass protects your data with a local encryption model.

Security

Safeguarding your data is what we do, with proactive security and reliability built in.