Guardian Inspection Payments

Responsible Disclosure

Responsible Disclosure

Help us keep Guardian and our customers safe. We appreciate the work of the security research community.

Introduction

Guardian Financial, aka Guardian Inspection Payments, a Porch Group company, values the work of security researchers in helping keep our systems and our customers’ data safe. If you believe you’ve found a security vulnerability in Guardian’s systems, we want to hear from you.

Contact

[email protected]

When submitting a report, please include:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Supporting materials (screenshots, proof-of-concept code, logs)
  • The affected URL, endpoint, or system component

What to expect

We will acknowledge your report within 2 weeks. Our security team will assess severity and impact as part of Guardian’s vulnerability management process, and may follow up for a retest once resolved.

Out of scope

Theoretical attacks without real-world impact, optional hardening recommendations, and disruptive testing such as denial-of-service attacks.

Safe harbor

Guardian will not pursue civil or criminal action against researchers who make a good-faith effort to comply with this policy, provided testing is limited to accounts or systems you own or have explicit permission to test.

Guardian does not currently offer monetary rewards, but valid reports may be credited in our Hall of Fame (with your permission).

Hall of Fame

No entries yet.