Mimecast’s Responsible Disclosure Policy
Mimecast considers protection of customer data a significant responsibility and requires our highest priority as we want to deliver our customers a remarkable experience along every stage of their journey. We therefore take the security of our systems extremely seriously, and we genuinely value the assistance of security researchers and others in the security community to assist in keeping our systems secure. Together we can make things better and find ways to solve challenges. Mimecast embraces on another’s perspectives in order to build cyber resilience. The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of all our users. If you discover a vulnerability, we would appreciate to hear from you in accordance with this Policy so we can resolve the issue as soon as possible. Together we can achieve goals through collaboration, communication and accountability.
For more information about our certifications please go to our trust center.
Guidelines For Responsible Disclosure
- Perform research only within the “In Scope” set out in this Policy;
- Mimecast Customers should Raise a Case for any reports that are not security related”
- To help us understand the nature and scope of the potential vulnerability, visit https://bugcrowd.com/ and complete the form with as much information as possible. When you're done, click Report Vulnerability to submit your report to Mimecast;
- Keep information about any vulnerability you’ve discovered confidential between yourself and Mimecast until we have had at least 90 days to review and resolve the issue. It is important to note that the timeframe for us to review and resolve an issue may vary based upon a number of factors, including the complexity of the vulnerability, the risk that the vulnerability may pose, among others;
- Keep communication channels open to allow effective collaboration;
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing
What You Can Expect From Us:
- We will work with you to understand and resolve the issue in an effort to increase the protection of our customers and systems;
- When you follow the guidelines that are laid out above, we will not pursue or support any legal action related to your research;
- We shall endeavour to respond to your report within 3 business days of submission
In Scope
- www.mimecast.com
- MTA Servers
- POP Servers
- Large File Send (LFS) service
- Secure Messaging (SM) service
- Unified Audit Utility
- Administration Console
- Personal Portal
- Service Monitor
- API
- Web Security
- DMARC Analyzer
- Aware
Out Of Scope
Any services hosted by third party providers are excluded from scope. These services include:
- Mimecast Knowledge Base (kb.mimecast.com);
- Mimecast Academy (academy.mimecast.com);
- https://community.mimecast.com;
- and anything else not explicitly named in the “In Scope” section above.
In the interest of the safety of our customers, staff, the Internet at large, as well as you as a security researcher, the following test types are excluded from scope:
- Any attempt to modify or destroy data;
- Findings derived primarily from social engineering (e.g. phishing);
- Findings from applications or systems not listed in the ‘In Scope’ section;
- Network level Denial of Service (DoS/DDoS) vulnerabilities or any other attempt to interrupt or degrade the services Mimecast offers, including impacting the ability for end users to use the service;
- Any attempts to access a user’s account or data;
- And anything not permitted by applicable law...
Qualifying Vulnerabilities
What is a “qualifying vulnerability”?Web application vulnerabilities such as XSS, XXE, CSRF, SQLi, Local or Remote File Inclusion, authentication issues, remote code execution, and authorization issues, privilege escalation and clickjacking. The vulnerability must be in one of the services named in the “In Scope” section above. You must be the first researcher to responsibly disclose the vulnerability and you must follow the responsible disclosure guidelines set out in this Policy, which include giving us a reasonable amount of time to address the vulnerability. We will confirm the reasonable amount of time with you following the disclosure of the vulnerability.
What is not a “qualifying vulnerability”?Although each submission will be evaluated on a case-by-case basis, here is a list of some of the issues which don’t qualify as security vulnerabilities:
- TLS/SSL related issues;
- SPF, DMARC, DKIM configurations;
- Security headers missing or Content-Security Policies (CSP);
- CAPTCHAs missing as a Security protection mechanism;
- Lack of flags on cookies;
- Username enumeration
- Vulnerabilities in end-of-life products;
- The ability to iFrame a page/clickjacking;
- HTML injection without any security impact;
- Account lockout or rate limit features;
- CSRF attacks without any impact or that do not cross a privilege boundary;
- Third party information/credential leaks that don't fall under Mimecast's control (e.g Google, Github, Pastebin etc);
- Mimecast Product email sensitive links indexed in third party services when disclosed by customers, directly or indirectly;
- Use of a known-vulnerable library without proof of exploitability;
- 3rd Party Vulnerabilities without advisory published or recently published (less than 30 days);
- Vulnerabilities that have already been reported/fix in progress;
- Subdomain takeover attacks without proof, a common false positive is smartlinggdn.mimecast.com;
- Host header injections when the attack vector needs MITM or when the header is not reflected;
- Information exposure (e.g Javascript files, API keys - Google maps) unless the data can be proven to be private;