How to report a security vulnerability to SYNE, and what to expect when you do.
We take the security of the SYNE platform seriously, including the risk, financial and climate data our customers trust us with. If you've found a security vulnerability affecting SYNE, we want to hear about it - this page explains how to report it, what we ask of you in return, and what you can expect from us.
This policy covers security vulnerabilities in systems that SYNE owns and operates directly, including syne.com, the SYNE platform and its constituent products (SYNE Climate Risk Management, Enterprise Sustainability, SYNE Trust, SYNE One and SYNE Plus), and the APIs described on our Developer Hub Pricing.
Independently governed data partners - such as Zixent, Teravent and Vivent, described on our Partners page - maintain their own security and disclosure practices. If you believe you've found an issue affecting one of these partners specifically, please contact them directly; we're happy to help route a report if you're unsure where it belongs.
Please report suspected vulnerabilities to security@syne.com. To help us investigate quickly, include where possible:
A clear description of the vulnerability and its potential impact.
Steps to reproduce it, including the affected URL, endpoint or product area.
Any supporting evidence, such as a screenshot, request/response log or proof-of-concept - without including real customer data beyond what's strictly necessary to demonstrate the issue.
If your finding involves sensitive detail, you're welcome to ask us for a PGP key before sending it.
We will not pursue legal action against, or refer to law enforcement, any researcher who discovers and reports a vulnerability in good faith and in accordance with this policy. We consider security research conducted under these terms to be authorised, and we will work with you to understand and resolve the issue quickly.
If a third party brings a claim against you for activity conducted in good-faith compliance with this policy, we will make clear to that party that your actions were authorised by us.
To keep testing safe for you, for us, and for our customers, please:
Avoid privacy violations. Don't access, modify, download or retain more customer data than is strictly necessary to demonstrate a vulnerability, and stop immediately once you've confirmed the issue exists.
Avoid service disruption. Don't run tests that could degrade or interrupt the Services for other users, including denial-of-service testing, and don't test against production customer accounts you don't own.
No social engineering or physical testing. Please don't attempt phishing, social engineering against SYNE personnel or customers, or physical access to our offices or facilities.
Give us time to respond. Please report a vulnerability to us before disclosing it publicly, and allow us a reasonable period to investigate and remediate before any public disclosure (see Section 5 below).
We aim to acknowledge new reports within two business days, and to provide an initial assessment of severity and next steps within five business days. We'll keep you updated as we investigate and remediate, and we'll let you know once a fix has been deployed.
For confirmed vulnerabilities, we ask for coordinated disclosure - we'll agree a reasonable disclosure timeline with you once the issue is understood, generally aiming to remediate before any public write-up, and we're happy to credit your work once it's safe to do so.
We're grateful to the researchers who take the time to report issues responsibly. Where you'd like recognition, and once a fix is in place, we're glad to credit your work publicly with your permission. This program does not currently offer paid bounties, though we may recognise exceptional reports at our discretion.
The following are generally not considered actionable under this policy: reports based purely on automated scanner output without a demonstrated, exploitable impact; vulnerabilities in outdated or unsupported browsers, or requiring an unlikely degree of user interaction; missing security headers or best-practice suggestions without a demonstrated vulnerability; rate-limiting or brute-force concerns on non-authentication endpoints; and reports concerning the security of an independently governed data partner (see Section 1 above), rather than SYNE's own systems.
Reach us at security@syne.com for anything covered by this policy. For all other enquiries, please use our Contact Us page.
See how we manage and protect customer data more broadly in our Data Management Policy, or get in touch with a different question.