Ready to hand off I-9 management?WorkBright+ pairs AI agents with compliance experts to run it for you.

Learn More
WorkBright Logo

Vulnerability Disclosure Policy

Last Updated: October 2, 2026

Purpose

WorkBright is committed to protecting the security and privacy of our customers, users, and systems.

We recognize that security researchers can play an important role in identifying vulnerabilities that may otherwise go undetected. This Vulnerability Disclosure Policy ("Policy") provides guidelines for conducting good-faith security research involving WorkBright systems and for responsibly reporting potential vulnerabilities to us.

Researchers must review, understand, and comply with this Policy before conducting security testing involving WorkBright systems.

Authorized Security Research

Security research conducted in accordance with this Policy is considered authorized by WorkBright.

To remain within the scope of this Policy, you must:

  • Conduct testing only to the extent reasonably necessary to identify and demonstrate the existence of a potential vulnerability.
  • Make every reasonable effort to avoid accessing, viewing, modifying, copying, downloading, transmitting, or deleting customer or user data.
  • Stop testing immediately if you encounter personal information, employee records, identity documents, credentials, financial information, or other sensitive or confidential information.
  • Notify WorkBright before conducting any test as well as within 48 hours of discovering any real or potential security vulnerability. Once you have confirmed that a vulnerability exists, or if you encounter sensitive or personal data, stop testing and notify WorkBright immediately.
  • Avoid disrupting WorkBright services or degrading the experience of our customers or users.
  • Give WorkBright a reasonable opportunity to investigate and remediate the issue before publicly disclosing it.
  • Comply with all applicable laws.

If you are uncertain whether a particular testing activity is permitted under this Policy, contact WorkBright before proceeding.

Security Research Guidelines

Researchers should use the least invasive means reasonably necessary to demonstrate a vulnerability.

A proof of concept should establish that a vulnerability exists without unnecessarily accessing actual customer or user information.

In particular, researchers must not:

  • Access customer or user accounts that they do not own or have explicit authorization to use.
  • Use credentials belonging to another individual, including credentials obtained from credential dumps, data breaches, the dark web, phishing, or other third-party sources.
  • Access, enumerate, retrieve, download, copy, or retain customer or employee records beyond what is minimally necessary to confirm a vulnerability.
  • Continue accessing records or accounts after establishing that unauthorized access is possible.
  • Exfiltrate data.
  • Modify or delete customer or user data.
  • Attempt to establish persistence within WorkBright systems.
  • Escalate privileges beyond what is minimally necessary to demonstrate the vulnerability.
  • Move laterally to other systems, accounts, customers, or environments.
  • Introduce malware or malicious code.
  • Conduct denial-of-service or resource-exhaustion testing.
  • Conduct high-volume automated testing that could affect the availability or performance of WorkBright systems.
  • Conduct social engineering, phishing, vishing, or physical security testing involving WorkBright employees, contractors, customers, or partners.
  • Test third-party systems or services that WorkBright does not own or control without authorization from the applicable third party.

If you encounter sensitive information while testing, stop immediately and notify WorkBright. Do not continue accessing the information for purposes of determining its scope or demonstrating additional impact unless WorkBright specifically authorizes you to do so.

Scope

This Policy applies to publicly accessible systems and services owned and operated by WorkBright.

This generally includes:

  • WorkBright web applications;
  • WorkBright-owned APIs;
  • WorkBright-owned public websites and domains; and
  • other Internet-accessible systems that WorkBright explicitly identifies as being within scope.

Third-party services, integrations, infrastructure, or applications are not automatically within scope merely because they are used by or integrated with WorkBright.

If you are unsure whether a particular system is within scope, contact WorkBright before conducting testing.

Reporting a Vulnerability

Please report suspected vulnerabilities to:

security@workbright.com

Please include enough information for our security team to understand and reproduce the issue, including, where applicable:

  • A description of the vulnerability.
  • The affected URL, API endpoint, product, or service.
  • The potential security impact.
  • Step-by-step instructions for reproducing the issue.
  • A limited proof of concept.
  • Relevant request and response information, with sensitive information removed or redacted.
  • Suggested remediation, if known.

Please do not include unnecessary personal information, customer data, employee records, authentication credentials, identity documents, or other sensitive information in your report.

What You Can Expect From Us

WorkBright takes good-faith vulnerability reports seriously.

When you submit a report consistent with this Policy, we will make reasonable efforts to:

  • Acknowledge receipt of your report within three business days.
  • Review and validate the reported issue.
  • Communicate with you if additional information is needed.
  • Keep you reasonably informed about the status of our investigation.
  • Work to remediate validated vulnerabilities based on their severity and risk.
  • Coordinate with you regarding disclosure of the vulnerability when appropriate.

Remediation timelines may vary depending on the complexity, severity, and potential impact of the issue.

Responsible Disclosure

Please do not publicly disclose a vulnerability or information obtained through a vulnerability until WorkBright has had a reasonable opportunity to investigate and remediate the issue and has provided written authorization for disclosure.

We ask that researchers coordinate disclosure with us so that customers and users are not unnecessarily placed at risk.

Safe Harbor

WorkBright supports good-faith security research.

If you conduct security research in compliance with this Policy, WorkBright will consider your activities authorized and will not initiate legal action against you based solely on those activities.

If WorkBright determines that your research was conducted in good faith but you accidentally exceeded the boundaries of this Policy, we will consider the circumstances and your efforts to minimize harm when determining how to respond.

This safe harbor applies only to claims that WorkBright has authority to waive or control. It does not authorize activity involving systems, data, or services owned by third parties, and WorkBright cannot authorize research on behalf of third parties.

Conduct that is malicious, intentionally harmful, extortionate, or materially inconsistent with this Policy is not authorized.

Bug Bounty and Compensation

WorkBright does not currently operate a formal public bug bounty program, and submission of a vulnerability report does not create an entitlement to compensation.

WorkBright may, at its discretion, provide recognition or a monetary award for reports that materially improve the security of our products or services.

Any award is discretionary and may take into account factors including the severity and quality of the report, the novelty of the vulnerability, the researcher's adherence to this Policy, and the manner in which the vulnerability was discovered and disclosed.

Researchers should not perform additional testing, access additional data, or increase the demonstrated impact of a vulnerability in an effort to qualify for or increase an award.

Activities Outside This Policy

This Policy does not authorize activity that is malicious, disruptive, unlawful, or inconsistent with the requirements above.

Examples include:

  • Accessing data beyond what is minimally necessary to demonstrate a vulnerability.
  • Accessing multiple customer accounts or records to demonstrate the scale of an issue.
  • Using compromised or stolen credentials.
  • Retaining or sharing customer or user data.
  • Extortion or threats involving disclosure of a vulnerability or data.
  • Demanding payment as a condition of deleting, withholding, or not disclosing information.
  • Disrupting WorkBright stervices.
  • Testing third-party systems without authorization.
  • Any activity prohibited by applicable law.

Activities outside the scope of this Policy may result in WorkBright taking actions it considers necessary to protect its customers, users, systems, and legal interests.

Changes to This Policy

WorkBright may modify this Policy at any time. Researchers should review the current version before conducting security research.

Questions

Questions about this Policy or whether particular research is permitted may be directed to: security@workbright.com

We welcome suggestions for improving this Policy and our vulnerability disclosure process.