Responsible Disclosure
How to report a security vulnerability in Orion, what to expect after you report it, and the safe harbor we extend to good-faith researchers.
- Version
- —
- Effective date
- —
- Last updated
- —
1. How to report a vulnerability
Email security@ultimatebillorganizer.com with the subject line “Security report”. Please include:
- A clear description of the issue and its potential impact.
- Step-by-step reproduction details, including the affected URL or screen.
- Any proof-of-concept request, payload, or screenshot that helps us confirm it.
- How you would like to be credited, if you want credit.
Please do not open a public issue, post details on social media, or contact customers directly before we have had a chance to fix the problem.
2. Security contact
Security reports: security@ultimatebillorganizer.com. This mailbox is monitored by JW Innovative Solutions LLC. For account, billing, or privacy questions use support@ultimatebillorganizer.com or privacy@ultimatebillorganizer.com instead.
3. Expected response times
We are a small team, so these are the targets we hold ourselves to rather than a contractual service level:
- Acknowledgement of your report: within 3 business days.
- Initial assessment and severity triage: within 10 business days.
- Status updates while we work: at least every 14 days until the report is closed.
- Remediation: critical issues are prioritized immediately; lower-severity issues are scheduled and tracked to closure.
4. Safe harbor
If you make a good-faith effort to follow this policy, we will not pursue legal action against you or ask your internet provider to do so, and we will treat your research as authorized.
- Test only against accounts you own or have explicit permission to use.
- Stay within the scope of proving the issue — do not access, modify, download, or retain another person's data.
- Do not run denial-of-service, spam, social-engineering, or physical attacks.
- Stop as soon as you have confirmed a vulnerability and report it.
- Delete any incidental data you obtained once the report is filed.
If you accidentally access customer data, stop immediately and tell us in your report. Reporting it honestly keeps you inside safe harbor.
5. Scope
- In scope: the The Ultimate Bill Organizer™ web application, its authenticated surfaces, its public pages, and its APIs.
- Out of scope: our third-party providers' own infrastructure (report those to the provider), missing best-practice headers with no demonstrated impact, results from automated scanners without a working proof of concept, and social engineering of our team or customers.
6. Disclosure process
- You report privately to security@ultimatebillorganizer.com.
- We acknowledge, reproduce, and assign a severity.
- We develop and ship a fix, then verify it with you where practical.
- We record the change internally and, where customers are affected, describe it in the Trust Center.
- Coordinated public disclosure is welcome after the fix ships — typically 90 days from the report, or sooner by mutual agreement.
7. Rewards
We do not currently operate a paid bug bounty program. We offer public credit on request and genuine gratitude, and we will say plainly if that changes.
8. No certification claims
Having a disclosure policy is not a certification. JW Innovative Solutions LLC does not hold SOC 2, ISO 27001, PCI DSS, or HIPAA attestation for this product, and we will not imply otherwise.
Version history
- v— · current · effective —
- No earlier versions have been archived.
Questions about this document? Email support@ultimatebillorganizer.com.