Part II: Responsible Disclosure Policy
16. Purpose
Fintant welcomes good-faith reports that help identify and correct security vulnerabilities. This Policy provides authorization only for research performed within the scope, rules, and reporting process below.
This is not a bug-bounty program. Fintant does not promise payment, public recognition, or a specific remediation result.
17. Authorized scope
Once this Policy is approved and published, authorized scope will include:
Fintant-owned production website and portal domains identified on Fintant’s published security page; and Fintant-owned production API endpoints used by those services.
The exact domains and API hosts must be inserted and verified before publication.
The following are out of scope unless Fintant gives separate written authorization:
development, test, staging, preview, demo, local, or internal environments; Fintant employee or contractor devices and accounts; third-party provider systems, including identity, email, scheduling, meetings, hosting, storage, scanning, monitoring, analytics, or AI services; client systems, accounting systems, bank systems, email tenants, and end-client systems; physical offices, facilities, networks, and personnel; denial-of-service, load, or destructive testing; and social engineering, phishing, pretexting, bribery, coercion, or physical intrusion.
If you are unsure whether a system is in scope, ask security@fintant.ai before testing.
18. Research rules
To remain within this Policy:
use only accounts and data you own or have explicit written permission to test; stop after confirming the minimum evidence needed to demonstrate the vulnerability; avoid accessing, downloading, retaining, altering, or deleting another person’s or organization’s data; do not establish persistence, move laterally, escalate beyond the minimum proof, or maintain unauthorized access; do not exploit a vulnerability for profit, leverage, publicity, competitive use, or any purpose beyond reporting; do not perform automated high-volume scanning, credential stuffing, password spraying, brute force, denial-of-service, resource exhaustion, or spam; do not upload malware or destructive payloads; do not disrupt service, corrupt data, alter accounting evidence, change approvals, or impair audit history; do not access provider secrets, production credentials, tax information, bank information, source documents, or financial records beyond the minimum unavoidable evidence; securely delete any inadvertently obtained Fintant data after Fintant confirms it is no longer needed; and keep the report and vulnerability confidential until Fintant authorizes disclosure or 90 days have passed after a complete report, whichever is later, unless law requires otherwise.
If your testing encounters Client Financial Data, credentials, internal notes, provider secrets, or another organization’s records, stop immediately and report the event.
19. How to report
Email security@fintant.ai with:
the affected domain, API, page, endpoint, parameter, or feature; the vulnerability type and potential impact; the date and time observed, including time zone; clear reproduction steps using non-sensitive evidence; relevant request and response details with credentials, tokens, cookies, personal information, and Client Financial Data removed; screenshots or proof-of-concept material only when necessary and safely redacted; whether any data was accessed and, if so, the minimum category and amount; actions already taken and whether the issue appears ongoing; and a safe way to contact you.
Do not send active credentials, session cookies, private keys, unredacted financial data, or malicious code by ordinary email. Ask for a secure transfer channel when needed.
20. Fintant’s response
For a complete, good-faith report, Fintant’s non-contractual operating targets are to:
acknowledge receipt within 5 business days; complete initial severity and scope triage within 10 business days; provide a status update at least every 15 business days while active, where practical; and coordinate a remediation and disclosure plan based on risk, complexity, provider dependence, and affected clients.
These are targets, not service levels or guarantees. Law, active exploitation, incident containment, third-party dependencies, or incomplete information may change the sequence.
Fintant may ask for clarification, validate the issue, combine duplicate reports, or determine that a report is informational, out of scope, accepted risk, or not reproducible.
21. Safe-harbor intent
When research is performed in good faith and complies with this Policy, Fintant intends to:
treat the research as authorized under this Policy; not initiate legal action against the researcher for accidental, good-faith violations promptly reported and corrected; and work with the researcher to understand and resolve the issue.
This authorization is limited. Fintant cannot authorize conduct on third-party or client systems, waive another party’s rights, bind law enforcement or regulators, or excuse conduct prohibited by applicable law. Extortion, threats, intentional privacy invasion, fraud, destructive action, public disclosure contrary to this Policy, or continued access after notice is not authorized.
If you are concerned whether proposed research is authorized, contact security@fintant.ai before proceeding.
22. Coordinated disclosure and recognition
Do not publicly disclose a vulnerability, affected system, client, data, proof of concept, or remediation detail until Fintant confirms that disclosure is safe and authorized.
Fintant may provide recognition at its discretion and only with the researcher’s consent. Fintant does not commit to a bounty or other compensation.
23. Changes and contact
Fintant may update this Policy as its systems and security program change. The version and effective date will be published, and material prior versions will be archived.
Security reports: security@fintant.ai Privacy questions: privacy@fintant.ai General support: support@fintant.ai Mail: Fintant Inc., 73-12 35th Avenue, Suite A45, Jackson Heights, NY 11372