Vulnerability Disclosure Policy

Aerial view of a marina canal at sunset with boats moored along both shores and a bridge crossing in the foreground.

Shorecliff Asset Management is committed to maintaining the security of our systems and protecting the information entrusted to us. We welcome reports of potential security vulnerabilities from security researchers and members of the public.

Reporting a Vulnerability

If you believe you have identified a security vulnerability affecting our website or systems, please notify us by email at it@shorecliffam.com.

Please include, where possible:

  • A description of the vulnerability.
  • The affected URL, system, or functionality.
  • Steps to reproduce the issue.
  • Any supporting screenshots, logs, or proof-of-concept information.

Our Commitment

Upon receiving a good-faith report, we will:

  • Acknowledge receipt within a reasonable timeframe.
  • Investigate and validate the reported issue.
  • Work to remediate confirmed vulnerabilities as appropriate.
  • Keep the reporter informed regarding the status of the report, where practical.

Good-Faith Research

We will not pursue legal action against individuals who conduct security research in good faith and in accordance with this policy, provided that they:

  • Make a reasonable effort to avoid privacy violations, data destruction, service disruption, or unauthorized access to customer or confidential information.
  • Do not exploit the vulnerability beyond what is reasonably necessary to demonstrate its existence.
  • Do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate it.

Scope

This policy applies to vulnerabilities affecting websites and online services owned and operated by Shorecliff Asset Management.

Exclusions

The following activities are outside the scope of this policy:

  • Social engineering, phishing, or physical security testing.
  • Denial-of-service or resource exhaustion attacks.
  • Spam or automated bulk submissions.
  • Testing of third-party systems or services not owned or operated by Shorecliff Asset Management.
  • Requests for compliance documentation, penetration test reports, or security questionnaires.

No Bug Bounty

Shorecliff Asset Management does not currently operate a bug bounty program and does not provide financial rewards for vulnerability reports.