Security & Vulnerability Disclosure Policy
Last updated: June 29, 2026
Ensju, operated by 17 Solutions LLC, takes the security of its monitoring platform and its customers' data seriously. We welcome reports from security researchers and run a coordinated Vulnerability Disclosure Program (VDP). This page explains how to report an issue, what is in scope, and the commitments we make to researchers who act in good faith.
1. Reporting a Vulnerability
Email security@ensju.com with a clear description of the issue, the affected URL or component, and the steps needed to reproduce it. Please include enough detail for us to confirm the finding.
We aim to acknowledge new reports within 3 business days and to keep you updated as we investigate and remediate. We do not currently offer PGP-encrypted intake; if your report contains especially sensitive details, let us know and we will arrange a secure channel.
2. Safe Harbor
We will not pursue or support legal action against you for security research conducted in good faith and in accordance with this policy, including good-faith, accidental violations. We consider such research to be authorized, and we will work with you to understand and resolve the issue quickly.
If a third party brings legal action against you for activity that complied with this policy, we will make it known that your actions were conducted in accordance with it. This safe harbor applies only to the activity described here; it does not waive any rights regarding conduct that falls outside it.
3. Scope
The following are in scope:
- The Ensju web application and API at ensju.com.
- Customer status pages served on *.ensju.com subdomains and verified custom domains.
- The Ensju server agent and probe worker as distributed by us.
The following are out of scope and should not be tested:
- Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks, and any automated load testing.
- Social engineering, phishing, or physical attacks against our staff, users, or facilities.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Findings that require a compromised device, a rooted/jailbroken mobile OS, or a man-in-the-middle position you control.
- Third-party services we rely on (e.g. Clerk, Stripe, our hosting and email providers) — please report those to the vendor directly.
- Best-practice suggestions with no security impact (e.g. missing headers without a concrete exploit, TLS configuration preferences, email SPF/DKIM nitpicks).
4. Rules of Engagement
To keep testing safe for our customers, please:
- Only interact with accounts and data you own or have explicit permission to test. Use a test account you control rather than another tenant's data.
- Stop immediately and report to us if you encounter any customer data that is not yours, and do not access, modify, save, store, transfer, or otherwise retain it.
- Limit a proof of concept to the minimum needed to demonstrate the issue — do not pivot, escalate, or maintain persistence.
- Never degrade, disrupt, or destroy data or service availability.
- Give us a reasonable opportunity to remediate before disclosing the issue publicly.
5. Coordinated Disclosure
We ask that you keep the details of any vulnerability confidential until we have had a reasonable time to fix it — typically up to 90 days from our acknowledgement, or sooner once a fix is deployed. We are happy to coordinate timing and public disclosure with you, and to credit you for the finding if you would like to be named.
6. Rewards
Ensju does not currently offer monetary rewards or a paid bug-bounty program. We deeply appreciate responsible disclosure, and — with your permission — we are glad to publicly acknowledge researchers who help us keep the platform secure.
7. Contact
Security reports: security@ensju.com. For non-security questions, please use support@ensju.com.