Vulnerability Disclosure Policy

Responsible security research and vulnerability reporting

Effective date: August 25, 2026 · Operator: TAS Group LLC

1. Purpose

TAS Group LLC welcomes responsible security research relating to TASVPN. Researchers should report suspected vulnerabilities to [email protected].

2. What to Include

  • A clear description of the suspected vulnerability
  • Affected product, service, endpoint, application or version
  • Steps necessary to reproduce the issue
  • Relevant screenshots, logs or proof-of-concept information that does not expose customer data
  • Potential security impact
  • Researcher contact information if follow-up is desired

3. Researcher Responsibilities

Researchers must not:

  • Intentionally access customer information
  • Modify or delete customer data
  • Disrupt production services
  • Perform denial-of-service testing
  • Install malware
  • Use social engineering
  • Publicly disclose an unresolved vulnerability before reasonable remediation coordination
  • Use discovered vulnerabilities for commercial exploitation or unlawful purposes

4. TASVPN Response

TASVPN will endeavor to acknowledge, triage, investigate, remediate and communicate regarding valid reports in a reasonable manner. Good-faith research performed within this policy will be evaluated accordingly.

5. Scope and Changes

TASVPN may update the scope of this policy as products and services evolve. Researchers should review the current policy before testing.

6. Contact

TAS Group LLC

30 N Gould St Ste N, Sheridan, WY 82801, United States

[email protected]