Enterprise cybersecurity
Enterprise
Report and Enterprise Cybersecurity
Responsible Disclosure Philosophy
Glory Global Solutions believes that the effective disclosure of security vulnerabilities relies on mutual trust, respect, transparency and a shared commitment to the common good between Glory Global Solutions and security researchers. Working together helps support the continued security and privacy of Glory Global Solutions’ customers, digital services, products and solutions.
Security Researchers
Glory Global Solutions welcomes vulnerability reports from responsible sources, including independent security researchers, industry partners, vendors, customers and consultants. For the purposes of this policy, a security vulnerability means an unintended weakness or exposure that could be used to compromise the integrity, availability or confidentiality of Glory Global Solutions’ digital assets, products, services or supporting systems.
We encourage responsible security research relating to Glory Global Solutions’ digital presence, services and products. You may conduct vulnerability research and testing only on Glory Global Solutions services and products to which you have authorised access. Your research and testing must not involve:
- Accessing, or attempting to access, accounts or data that does not belong to you
- Any attempt to modify or destroy any data that does not belong to you
Executing, or attempting to execute, any denial-of-service attack
Testing in a way that would degrade, disrupt or impair the operation of any Glory Global Solutions systems, services or customer-facing platforms
Sending unsolicited or unauthorised email, spam or junk email
Testing third-party applications, websites or services that integrate with Glory Global Solutions or connect to Glory Global Solutions systems, unless you have explicit authorisation to do so
- Posting, transmitting, uploading, linking to, sending, or storing any malicious software
Scope
This programme applies to Glory Global Solutions’ digital presence, including digital assets owned, operated or maintained by Glory Global Solutions, such as websites, online services, applications and supporting digital platforms. It also applies to digital services that could reasonably affect the security of Glory Global Solutions, its customers or users. Product-specific vulnerability reports should include enough detail to help Glory Global Solutions understand the affected product, service, software version, configuration and potential impact.
Our Commitment to Researchers
- Trust. We maintain trust and confidentiality in our professional exchanges with security researchers.
Respect. We treat all researchers with respect and recognise your contribution to helping keep our customers, users, products and digital services safe and secure.
Transparency. We will work with you to validate and remediate reported vulnerabilities in line with our commitment to security, privacy and responsible disclosure.
- Common Good. We investigate and remediate issues in a manner consistent with protecting the safety and security of those potentially affected by a reported vulnerability.
What We Ask of Researchers
- Trust. We request that you communicate about potential vulnerabilities in a responsible manner, providing sufficient time and information for our team to validate and address potential issues.
Respect. We ask researchers to make every effort to avoid privacy violations, disruption to production systems, degradation of user or customer experience, and destruction or alteration of data during security testing.
- Transparency. We request that researchers provide the technical details and background necessary for our team to identify and validate reported issues, using the form below.
- Common Good. We request that researchers act for the common good, protecting user privacy and security by refraining from publicly disclosing unverified vulnerabilities until our team has had time to validate and address reported issues.
Vulnerability Reporting
Glory Global Solutions asks security researchers to share details of any suspected vulnerabilities affecting assets owned, controlled or operated by Glory Global Solutions, or that could reasonably affect the security of Glory Global Solutions, its customers or users, using the reporting process provided. The Glory Global Solutions security team will acknowledge receipt of each vulnerability report, review the information provided, investigate the issue and take appropriate steps towards resolution.
By submitting a vulnerability report, you acknowledge that Glory Global Solutions values your input but does not commit to providing monetary rewards, and no reward should be expected.