Effective date: 04/08/2026
Purpose
SUSOS is committed to reducing risk for users and organizations by handling vulnerability reports responsibly. This policy describes how security researchers and others can report vulnerabilities to us, how we handle reports about our own services (this site and SUSOS‑operated offerings), and how we conduct coordinated disclosure for vulnerabilities we discover in third‑party products and services within our CNA scope.
Scope
This inbox and policy apply to security issues in:
Out of scope (without prior written authorization)
How to report
Email help@susos.co with:
What we ask of researchers
Our commitment
We will acknowledge receipt within 5 business days when possible. We will investigate validated reports, work on remediation where we control the code or configuration, and coordinate disclosure timelines with you. We may credit researchers in advisories if you want recognition.
Safe harbor
If you comply with this policy and applicable law, SUSOS will not pursue civil action or refer you for law enforcement action for accidental, good‑faith research that does not harm users or our operations. This safe harbor does not bind third parties.
Coordinated disclosure for third‑party products (CNA activity)
When SUSOS discovers vulnerabilities in third‑party products or services through authorized research or customer engagements, we follow coordinated disclosure practices consistent with the CVE Program and applicable CNA Rules. Public write‑ups for those issues, when published, will be listed on our Security advisories page: https://susos.co/security-advisories
Changes
We may update this policy; the “Effective date” at the top will reflect the latest version.
Show Up Show Out Security ®
2125 Biscayne Blvd, Ste 204 #10150 Miami, Florida 33137
Copyright © 2026 Show Up Show Out Security ® - All Rights Reserved.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.