Vulnerability Disclosure Policy — TalaStar Digital
🔒 Security

Vulnerability Disclosure Policy

We build safeguarding infrastructure. We take security seriously. If you find a vulnerability, we want to hear from you.

📅 Effective: 25 May 2026 🔄 Review cycle: Annual ⏰ Response SLA: 72 hours

Contents

  1. Scope
  2. Safe Harbor
  3. How to Report
  4. PGP Key
  5. Disclosure Timeline
  6. What’s Not Permitted
  7. Recognition & Rewards
  8. security.txt
  9. Email Alias Setup

1Scope

The following assets are covered by this policy. Researchers who discover vulnerabilities in in-scope assets and follow this policy will receive our full cooperation and recognition.

✅ In Scope

  • All *.talastar.digital subdomains
  • TalaStar deployments at *.polsia.app
  • Published APIs at /api/v1/*
  • Authentication & session management
  • Data storage & encryption layers
  • TalaStar Data Sovereignty Engine
  • MoneyGuard PWA security surface
  • Cyber-Resilience Core agents
  • IRIS Orchestrator Hub API

🚫 Out of Scope

  • Third-party services (Stripe, Postmark, OpenAI)
  • Denial of Service (DoS / DDoS)
  • Social engineering attacks
  • Physical access attacks
  • Automated scanners at high rate against production
  • Clickjacking on non-sensitive pages
  • Self-XSS requiring user interaction
  • Issues requiring MITM on victim’s network
  • Bruteforce attacks

2Safe Harbor

TalaStar Digital Ltd supports safe security research. We will not pursue civil or criminal action against researchers who follow this policy in good faith.

We consider security research conducted under this policy to be:

✔  Authorised under the Computer Misuse Act 1990 and equivalent legislation, provided research stays within scope and follows this policy.

✔  Exempt from DMCA anti-circumvention provisions to the extent the research is necessary to identify and report a vulnerability.

✔  Conducted in good faith — we will work with you to understand and resolve the issue quickly, and will not take action against researchers for accidental, good-faith violations.

If you are uncertain whether your research qualifies under this safe harbor, contact us before proceeding: security@talastar.digital

This safe harbor statement is based on the Disclose.io model safe harbor.

Conditions for safe harbor to apply:

3How to Report

Send your report via email. Include as much detail as possible: affected asset, steps to reproduce, impact assessment, and any proof-of-concept code.

📧 Primary email
🌐 Web form
/security (this page)
🔑 PGP encryption
Fingerprint: 3C40 030F 316B D2AC 987F 9925 D51F CA08 6001 78E8
⏰ Initial response
Within 72 hours — acknowledgment that we received your report
📈 Status update
Within 7 days — triage outcome, severity rating, and remediation plan
📋 Report format
Plain text or encrypted PGP. No special form required.

Please include in your report:

4PGP Key

Encrypt sensitive vulnerability reports with our security team’s public key. The key is also available at /.well-known/pgp-key.txt.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Comment: TalaStar Digital Ltd — security@talastar.digital
Version: TalaStar Security 2026

BGoTkQAWp7JyBQQ7XmMLc+rRVt7E7kT3cN3l3+6XbQlFQyb80S4A
=HMfC
-----END PGP PUBLIC KEY BLOCK-----
Key Type:    Ed25519
Key ID:      D51FCA08600178E8
Fingerprint: 3C40 030F 316B D2AC 987F  9925 D51F CA08 6001 78E8
Created:     2026-05-25
Expires:     2028-05-25
UID:         TalaStar Security <security@talastar.digital>

5Coordinated Disclosure Timeline

We follow a 90-day coordinated disclosure standard. The timeline begins from the date we confirm receipt of a valid, reproducible report.

1

Day 0 — Report received

You submit your report. The clock starts when we confirm receipt.

2

Day 1–3 — Acknowledgment & triage

We confirm receipt within 72 hours and begin triage. You receive an initial severity assessment within 7 days.

3

Day 7–30 — Remediation sprint

For critical and high severity issues we aim to patch within 30 days. We’ll keep you updated on progress.

4

Day 30–90 — Patch deployed

Medium and low severity issues remediated within 90 days. We notify you when the patch is live.

5

Day 90 — Public disclosure

After remediation or at Day 90 (whichever comes first), you are free to publish. We may request a brief extension for critical infrastructure findings affecting NHS or clinical systems — this is always negotiated, never imposed.

If we cannot reproduce a vulnerability or need more time on a critical infrastructure finding, we will negotiate in good faith. We will never use a deadline extension to avoid accountability.

6What’s Not Permitted

The following activities are not authorised under this policy and will not be covered by safe harbor:

💥

High-rate automated scanning

Do not run automated scanners (Burp, Nuclei, sqlmap) against production systems at a rate that degrades availability. Use targeted, low-rate requests only.

🕵️

Accessing user data

Do not access, download, or exfiltrate data belonging to other users. Stop at proof-of-concept — demonstrate the vulnerability without extracting real data.

🛠️

Persistence & backdoors

Do not install backdoors, web shells, or persistent access mechanisms. Report the vulnerability and stop.

🌐

Lateral movement

Do not pivot from one system to another. Scope your testing to the reported asset only.

💼

Social engineering

Do not target TalaStar employees or contractors with phishing, pretexting, or other social engineering techniques.

Denial of Service

Do not conduct DoS or DDoS testing. These attacks are not covered under this policy regardless of intent.

7Recognition & Rewards

TalaStar Digital operates a recognition-only programme at this stage. There are no cash bounties. This is honest — we are a Series 0 clinical AI company and our security budget goes into building the product.

🏆 Hall of Fame

Researchers who disclose valid, impactful vulnerabilities will be credited publicly in our Hall of Fame (with their consent) and thanked in our security changelog.

Hall of Fame page coming soon. Your name will be here first.

What researchers receive:

We will revisit paid bounties as the company scales. If you find something critical that materially protects our NHS or clinical partners, we will make sure you are remembered for it.

8RFC 9116 security.txt

Our security.txt is served at /.well-known/security.txt per RFC 9116.

# TalaStar Digital Ltd — Vulnerability Disclosure Policy
# RFC 9116 compliant security.txt

Contact: mailto:security@talastar.digital
Contact: https://talastar-digital-ltd.polsia.app/security
Expires: 2027-05-25T21:00:00.000Z
Encryption: https://talastar-digital-ltd.polsia.app/.well-known/pgp-key.txt
Preferred-Languages: en
Policy: https://talastar-digital-ltd.polsia.app/security
Canonical: https://talastar-digital-ltd.polsia.app/.well-known/security.txt

9Email Alias Setup

The address security@talastar.digital must be routable to receive vulnerability reports. If it is not yet active, follow one of these setup paths:

Option A — DNS forwarding (Google Workspace / Zoho / Cloudflare Email Routing)

Option B — Postmark inbound routing

Option C — SimpleForward (minimal DNS record)

Note: Until security@talastar.digital is live, researchers can also use the web contact page or reach out through the main company contact. Private key for the PGP keypair generated on 2026-05-25 was delivered as a one-time artifact to the operator and must be stored offline — do not commit to any repository.