Our Commitment to Security
At Vanguard, protecting our clients, systems, and data is a top priority. We recognize the important role that independent security researchers play in helping identify potential security vulnerabilities.
We welcome and encourage the vulnerability disclosure of security issues. This Vulnerability Disclosure Program is intended to provide a clear, secure, and constructive pathway for reporting potential vulnerabilities in our systems, applications, and services.
Program Overview
Before participating in our program, please review the vulnerability disclosure program guidelines to understand the defined scope, program rules, and submission criteria, including the types of submissions that may be considered ineligible or out of scope. This program enables security researchers to responsibly report potential security vulnerabilities while ensuring that:
- Reports are reviewed and validated in a timely manner
- Vulnerabilities are remediated appropriately
- Researchers are protected when acting in good faith
How to Report a Vulnerability
If you believe you have identified a potential security vulnerability, please submit a report including:
- A detailed description of the issue
- The affected asset or endpoint
- Steps to reproduce the issue
- Supporting materials (e.g., screenshots, logs, proof-of-concept)
Vanguard uses HackerOne to triage and validate responsibly disclosed vulnerability reports. Please submit your report via HackerOne - https://hackerone.com/vanguard.
Submitting your report via HackerOne will help ensure timely validation.