Embarc

Door-to-door fiber sales. Built for reps who follow opportunity.

/ Security

Responsible Vulnerability Disclosure

Last updated: July 6, 2026

Embarc Solutions ("Embarc") takes the security of our systems, our carrier partners, and their subscribers seriously. We welcome reports from security researchers, customers, and members of the public who identify potential vulnerabilities in our website or the systems we operate. This policy explains how to report a suspected vulnerability, what you can expect from us, and the safe harbor we extend to good-faith researchers.

Scope

This policy applies to:

  • The Embarc Solutions website and any subdomains we operate.
  • Internal tools and infrastructure operated by Embarc Solutions.
  • Applications and forms we publish for representatives, partners, and carriers.

Payment processing and cardholder data environments are operated by our carrier partners and their PCI DSS-compliant payment processors. Embarc does not store, process, or transmit cardholder data on its own systems. Vulnerabilities in third-party carrier or processor platforms should be reported directly to that provider; we are happy to help route reports where appropriate.

How to Report

Email a detailed report to security@embarcsolutions.com. Please include:

  • A clear description of the vulnerability and the potential impact.
  • Step-by-step instructions to reproduce the issue, including URLs, request payloads, and any accounts used.
  • Screenshots, logs, or proof-of-concept code where helpful.
  • Your name or handle and how you would like to be credited (optional).

If the report is sensitive, request our PGP key in your initial message and we will provide one for encrypted follow-up.

Our Commitment

  • We will acknowledge receipt of your report within 3 business days.
  • We will provide an initial assessment and expected next steps within 10 business days.
  • We will keep you informed as we investigate and remediate the issue.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • With your permission, we will publicly credit you once the issue is resolved.

Safe Harbor

We consider security research and vulnerability disclosure activities conducted consistent with this policy to be authorized conduct. We will not pursue civil or criminal action, or report to law enforcement, for good-faith violations of this policy. If a third party initiates legal action against a researcher who has complied with this policy, we will make it known that the activity was authorized.

Rules of Engagement

To stay within safe harbor, researchers must:

  • Make a good-faith effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only interact with accounts you own or have explicit permission from the account holder to access.
  • Stop testing and notify us immediately if you encounter cardholder data, personal information, or other sensitive records.
  • Not exfiltrate any data beyond the minimum necessary to demonstrate the vulnerability, and delete any such data as soon as the report is submitted.
  • Give Embarc a reasonable opportunity to remediate before publicly disclosing the issue.

The following activities are out of scope and are not authorized:

  • Denial-of-service, resource exhaustion, or volumetric testing.
  • Social engineering of Embarc employees, representatives, carrier partners, or subscribers.
  • Physical attacks against Embarc property or personnel.
  • Automated scanning that generates significant traffic without prior written coordination.
  • Testing against carrier, processor, or other third-party systems.

Out of Scope Findings

  • Missing security headers or best-practice hardening without a demonstrable impact.
  • Reports from automated scanners without a working proof of concept.
  • Rate-limiting or brute-force issues on non-authentication endpoints.
  • Self-XSS and issues that require an already-compromised device.
  • Publicly known vulnerabilities in third-party software for which no patch is yet available, absent a working exploit against Embarc.

Contact

Security reports: security@embarcsolutions.com. General inquiries: contact@embarcsolutions.com.