Responsible Disclosure Policy
- Effective Date: August 5, 2026
- Last updated: August 6, 2026
1. Purpose
Aptora Corporation is committed to protecting the security of our products, services, and customer information.
If you believe you have discovered a security vulnerability in an Aptora product or service, we encourage you to report it responsibly so we can investigate and address the issue.
This policy explains how to report security vulnerabilities and what you can expect from us.
2. Scope
This policy applies to security vulnerabilities involving:
- Aptora websites
- Aptora 360
- Total Office Manager
- Customer portals
- Mobile applications
- Public APIs
- Cloud-hosted services owned or operated by Aptora
This policy does not authorize testing against customer-owned systems, customer databases, or third-party services.
3. Reporting a Vulnerability
Please report suspected vulnerabilities by email to:
helpdesk@aptora.com
Include as much information as possible, including:
- A description of the issue.
- The affected product or service.
- The software version, if known.
- Steps to reproduce the issue.
- Screenshots or supporting documentation, if available.
- Your name and contact information if you would like us to respond.
Reports that contain clear and complete information help us investigate more quickly.
4. Our Commitment
When we receive a vulnerability report, we will make reasonable efforts to:
- Acknowledge receipt of your report.
- Review the information provided.
- Investigate the reported issue.
- Determine the appropriate corrective action.
- Keep you informed of significant progress when practical.
- Correct validated vulnerabilities as our business priorities and risk assessments allow.
Not every reported issue will be determined to be a security vulnerability.
5. Good Faith Research
We support responsible security research conducted in good faith.
We ask that you:
- Respect the privacy of our customers.
- Avoid accessing, copying, or modifying customer data.
- Do not intentionally disrupt our services.
- Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate its existence.
- Stop testing if you discover customer information and notify us immediately.
- Allow us a reasonable opportunity to investigate and resolve the issue before publicly disclosing it.
6. Activities That Are Not Permitted
The following activities are not authorized under this policy:
- Accessing customer accounts without permission.
- Downloading, copying, or modifying customer data.
- Social engineering of customers or employees.
- Physical attacks on facilities or equipment.
- Denial-of-service (DoS) or distributed denial-of-service (DDoS) testing.
- Malware or ransomware testing.
- Password attacks or credential stuffing.
- Spam or phishing campaigns.
- Introducing malicious software into our systems.
- Any activity that violates applicable law.
7. Safe Harbor
If you conduct security research in accordance with this policy, act in good faith, comply with applicable law, and avoid harming Aptora, our customers, or our services, Aptora will not intentionally pursue legal action solely because of your responsible disclosure activities.
This safe harbor applies only to activities that comply with this policy and does not authorize access to customer information, employee accounts, or systems beyond what is reasonably necessary to identify and report a potential vulnerability.
8. Public Disclosure
We ask that you do not publicly disclose a reported vulnerability until:
- We have completed our investigation;
- The vulnerability has been remediated, if applicable; or
- We mutually agree that public disclosure is appropriate.
Coordinated disclosure helps protect our customers while allowing time to address security issues responsibly.
9. Bug Bounty
Aptora appreciates responsible vulnerability reports.
At this time, Aptora does not operate a bug bounty or financial reward program, and submission of a vulnerability report does not create any expectation of compensation.
10. Questions
Questions regarding this policy or the reporting of security vulnerabilities may be directed to:
Aptora Corporation
Attn: Information Security Officer
8877 Bourgade Avenue
Lenexa, Kansas 66219
Email: helpdesk@aptora.com
Phone: (913) 492-9930

