Security & Vulnerability Disclosure Policy
Last Updated: May 5, 2026
Our Commitment to Security
Procomm 360 takes the security of our systems and customer data seriously. We implement industry-standard security controls including multi-factor authentication, encryption at rest and in transit, immutable audit logging, role-based access control, and automated vulnerability scanning. Our platform undergoes continuous security monitoring through Aikido Security.
Reporting a Vulnerability
If you believe you have found a security vulnerability in any Procomm 360 service, we encourage you to report it to us responsibly. We appreciate your help in keeping our platform and customers safe.
How to Report
- Email: security@procomm360.com
- Subject line: Include "[Vulnerability Report]" in the subject
- Encryption: If you need to send sensitive details, request our PGP key at the same email address
What to Include
Please provide enough information to reproduce the issue so we can resolve it quickly:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The URL or component affected
- Any supporting material (screenshots, proof-of-concept code, logs)
- Your contact information for follow-up
Our Response Process
Acknowledgment within 48 hours
We will confirm receipt of your report and assign a tracking reference.
Triage within 5 business days
Our security team will validate the report, assess severity, and determine a remediation timeline.
Remediation
We aim to fix critical issues within 7 days and high-severity issues within 30 days.
Notification
Once fixed, we will notify you and, where appropriate, publicly acknowledge your contribution.
Safe Harbor
We support responsible security research. If you follow these guidelines, we will:
- Not pursue legal action against you for your research
- Work with you to understand and resolve the issue quickly
- Recognize your contribution if you wish to be credited
Guidelines for Researchers
- Do not access, modify, or delete data belonging to other users
- Do not perform denial-of-service attacks or degrade service for other users
- Do not use social engineering against our employees or customers
- Do not publicly disclose the vulnerability before we have had a reasonable time to fix it (90 days)
- Only test against accounts you own or have explicit permission to test
Scope
This policy applies to the following Procomm 360 assets:
- The Procomm 360 web application and all associated subdomains
- APIs and backend services
- The Client Portal
- Public-facing forms (contact, merchant application, invoice payment)
Third-party services we use (e.g., NMI, Authorize.Net, Plaid, Twilio, Base44) are outside the scope of this policy. Please report vulnerabilities in those services directly to the respective vendors.
Contact
Procomm 360 Security Team
Email: security@procomm360.com
Phone: (866) 405-5838
For non-security inquiries, please contact admin@procomm360.com.
