Vulnerability Disclosure Policy
Effective date: September 1, 2026 · Version 2026-09-01
PALDAM LLC welcomes reports that help us protect CivicRecordsOnline. This policy explains how to report a suspected vulnerability and the conditions for authorized good-faith security research. It is not a bug-bounty offer, contract for payment, permission to access data belonging to others, or waiver of rights beyond the express safe harbor below.
Systems in scope
The staff application at app.civicrecordsonline.com. The requester account portal at my.civicrecordsonline.com. Agency public portals PALDAM hosts for its customers on tenant subdomains of civicrecordsonline.com. The marketing site at civicrecordsonline.com and www.civicrecordsonline.com. PALDAM operates a companion brand of the same Service; the corresponding hosts under that brand's domain, and the default cloud hostnames that serve the same application, are in scope on the same terms.
Out of scope
Any host not listed above, including any non-production, staging, test, or development environment. Third-party services PALDAM relies on, including Microsoft Azure, Cloudflare, Stripe, Twilio SendGrid, and Google, which operate their own disclosure programs. Findings that depend on a customer's own configuration choices or require a compromised customer account.
Test only with accounts, trial workspaces, requests, and files that you created and control. Report a vulnerability in a third-party service to that provider.
Rules for research
Use the minimum testing needed to confirm a vulnerability. Do not exploit it beyond that point.
Stop immediately if you encounter another person's or agency's data. Do not view more than necessary to recognize the exposure; do not copy, download, retain, transmit, alter, delete, or disclose it.
Do not access another tenant, requester, staff account, private workspace, unredacted record, credential, token, secret, or personal information.
Do not use denial of service, load or stress testing, automated high-volume scanning, password spraying, credential stuffing, brute force, malware, persistence, lateral movement, social engineering, phishing, physical intrusion, or supply-chain attacks.
Do not disrupt the Service, degrade another user's experience, send unsolicited messages, create fraudulent records, incur charges, or damage data.
Do not violate law, bypass a technological control when doing so is unlawful, or test from a jurisdiction where the activity is prohibited.
Keep the report and vulnerability confidential until PALDAM confirms remediation or gives written permission to disclose. Coordinate any proposed disclosure with us. Do not publicly disclose personal data, Agency Data, credentials, exploit code that creates ongoing risk, or details that would materially increase risk to users.
How to report
Email security@civicrecordsonline.com. Include the affected URL or component, prerequisites, clear reproduction steps, observed impact, and any minimal proof of concept. Remove personal information and Agency Data from screenshots or logs. Tell us whether you believe active exploitation is occurring. If ordinary email is inappropriate for the sensitivity of the report, ask for a secure transfer method before sending sensitive material.
PALDAM aims to acknowledge a complete report within 5 business days, but this is a target rather than a contractual deadline. We may request clarification, combine duplicate reports, prioritize based on risk, and communicate remediation information at a level consistent with security and third-party confidentiality.
Safe harbor
PALDAM authorizes security research on the in-scope systems that follows this policy. If you make a good-faith effort to comply with this policy while researching and reporting, PALDAM will treat your research as authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. If a third party, including a customer agency, brings legal action against you for research that complied with this policy, PALDAM will make it known that your activity was authorized. This safe harbor does not extend to research that exceeds the scope or rules stated here, that accesses or retains data beyond what is needed to demonstrate a vulnerability, or that violates a law PALDAM has no authority to waive.
No bounty or obligation
PALDAM does not currently operate a paid bug-bounty program and has no obligation to pay, provide credit, accept a report, implement a proposed fix, disclose internal information, or meet a requested publication schedule. PALDAM may recognize a confirmed reporter at its discretion and only with the reporter's consent.
Data handling
If a report contains information that PALDAM must preserve for security, legal, insurance, or incident-response purposes, PALDAM may retain and share it with affected agencies, service providers, professional advisers, insurers, or authorities as reasonably necessary. Do not send information you are not authorized to possess.
This page is informational. It describes current practices, is subordinate to the Terms of Service, and — apart from the express safe harbor above — does not create independent warranties or contractual commitments.