RESPONSIBLE DISCLOSURE
Vulnerability disclosure program
Security researchers strengthen the systems that federal agencies depend on. If you believe you have found a vulnerability in an Internet-accessible Knox system, we want to hear from you. This policy tells you what is authorized, what is in scope, and how to report.
Safe Harbor Authorized
Anonymous Reports Accepted
Acknowledgement within 3 business days
Introduction
Knox operates the biggest, longest-running FedRAMP cloud. The security of that boundary is the foundation of our work with U.S. federal agencies, and security researchers play an important role. Knox welcomes reports of vulnerabilities observed in internet-accessible Knox information systems, applications, or websites.
Information submitted under this policy is used for disclosure purposes only. We use it to mitigate or remediate vulnerabilities in our systems. This safe-harbor policy applies to all good-faith research. If you are unsure whether particular conduct is permitted, contact us before proceeding.
Authorization
If you make a good-faith effort to comply with this policy during your security research, we consider your research authorized. We will avoid activity against you under applicable law and Knox will not initiate or pursue legal action related to your research.
SAFE HARBOR
Should a third party initiate legal action against you for activities conducted in accordance with this policy, we will make this authorization known.
Guidelines
- Notify us as soon as possible after you discover a material potential security issue.
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
- Use exploits only to the extent necessary to confirm a vulnerability. Do not use an exploit to compromise or exfiltrate data, establish persistent access, or pivot to other systems.
- Stop your test and notify us immediately if you encounter personally identifiable information, confidential or sensitive information, or credentials. Do not save, copy, transfer, or disclose such data
- Do not disclose any incidental proprietary or intellectual property data revealed during testing, or the content of information made accessible by a vulnerability, to any party that was not already aware of that information at the time the report is submitted to Knox Systems.
- Comply with all applicable federal, state, and local laws in connection with security research activities or any other participation in this vulnerability disclosure program.
- Provide us a reasonable amount of time to remediate the issue before you disclose it publicly.
- Do not submit a high volume of low-quality reports, media, or redundant components in a single report.
Restricted test methods
The following test methods are not authorized under this policy:
- Network denial of service (DoS or DDoS) or any test that impairs access to or damages a system or data.
- Physical interaction with offices or resources, such as office access, data centers, or facilities.
- Social engineering of Knox personnel or customers, including phishing, vishing, and smishing.
- Any other test technique that would be harmful or disruptive.
Reporting a vulnerability
Submit reports through the vulnerability disclosure form below, or by email to security@knoxsystems.com. Reports may be submitted anonymously. If you share contact information, we will use it only to communicate on your report and will not share it without your express permission.
A useful report includes:
- The system, URL, or IP address where the vulnerability was observed.
- A description of the vulnerability and its potential impact.
- Detailed steps to reproduce, including any relevant proof-of-concept steps or screenshots.
- Whether the vulnerability has been disclosed to anyone else.
What you can expect from us
When you choose to share contact information with your report, we commit to communicating with you as openly and as quickly as possible:
We acknowledge receipt of your report within 3 business days.
We confirm the nature of the reported vulnerability and remain transparent about remediation steps, including any factors that may delay resolution.
We maintain an open dialogue about status.
We notify you after the vulnerability is remediated.
Coordinated Disclosure
We ask that you allow Knox 90 days from the date of your report to remediate the vulnerability publicly. Disclosure timing and coordination depend on the severity of the vulnerability, potential impact to federal customers, available mitigations, and the time required for agencies to apply a fix.
This program does not provide compensation. Submitting a report creates no entitlement to payment or future business with Knox. We may, at our discretion, recognize researchers who report high-impact vulnerabilities.
Questions?
Questions regarding this policy’s scope or the status of a submitted report may be sent to security@knoxsystems.com. Suggestions for improving this policy are welcome.
Report a Vulnerability
Use this form to report a vulnerability on an in-scope Knox system. Contact information is optional. Reports are reviewed by the Knox security team and used for defensive purposes only.

