Vulnerability Disclosure Policy

Last updated: May 29, 2026

Introduction

Massey Media Inc takes the security of its software seriously. We welcome reports from security researchers, customers, and the broader community about vulnerabilities in our products. This policy describes how to report a vulnerability, what to expect from us in response, and the protections we offer to researchers acting in good faith.

This policy is published in accordance with ISO/IEC 29147 (Vulnerability disclosure) and supports our obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act).

Scope

This policy covers all software products and services published by our organization. If you are unsure whether a particular property is in scope, please contact us before testing.

How to report a vulnerability

Email reports to: [email protected]

When you report a vulnerability, please include:

  • A description of the issue, including the affected product and version.
  • Steps to reproduce, with proof-of-concept code or screenshots where possible.
  • Your assessment of the impact (data exposure, privilege escalation, denial of service, etc.).
  • Whether you have shared the issue with any third party (CERT, CVE Numbering Authority, other vendor).
  • How you would like to be credited if and when we publish the advisory.

What you can expect from us

  • We will acknowledge your report within 72 hours.
  • We will provide an initial assessment of severity and an estimated timeline within five business days.
  • We aim to develop, test, and release a fix within 90 days for high-severity issues. Low-severity issues may take longer.
  • We will keep you informed of progress at reasonable intervals.
  • We will credit you in the published advisory if you wish.

Coordinated disclosure

We follow coordinated disclosure practices. We ask that you give us a reasonable opportunity to release a fix before publishing details of the vulnerability. We will coordinate the public disclosure timeline with you and credit your contribution if you agree.

Safe harbor

We consider security research conducted in good faith and in accordance with this policy to be authorized activity. We will not pursue civil or criminal action against researchers who:

  • Make a good-faith effort to follow this policy.
  • Avoid harm to our customers, employees, or third parties.
  • Avoid accessing or modifying data that does not belong to them.
  • Stop testing and notify us immediately upon discovery of any vulnerability that exposes customer or personal data.
  • Do not disclose the vulnerability publicly before we have had a reasonable opportunity to remediate it.

This safe harbor does not cover activity that is unlawful or that targets accounts, data, or systems beyond those owned by our organization.

Out-of-scope behavior

  • Denial-of-service or load testing without prior written consent.
  • Social engineering of our staff, customers, or partners.
  • Physical attacks against our offices or property.
  • Accessing, modifying, or destroying data that does not belong to you.
  • Publicly disclosing a vulnerability before a fix has been released.

Contact

Massey Media Inc
[email protected]
10 Woodhue Ct
Lufkin, TX, 75904
USA