Home / Security Disclosure Policy
Security Disclosure Policy
Thrive Creative Inc. welcomes reports of security vulnerabilities affecting our website and the infrastructure we operate. This page explains what we consider in scope, how to report responsibly, and what you can expect from us in return.
This policy complements the machine-readable version at /.well-known/security.txt (RFC 9116).
In scope
- thrivecreative.ltd and all subdomains we operate
- Our WordPress theme (
thrive-blocks), custom plugins (thrive-sales-dashboard,thrive-lead-router), and mu-plugins - REST and webhook endpoints on
www.thrivecreative.ltdandsales.thrivecreative.ltd - Our configuration and deployment of any self-hosted service we run (including our Twenty CRM and GitLab instances)
Out of scope
- Upstream vulnerabilities in third-party software we self-host (WordPress core, Twenty CRM, GitLab). Please report those to the respective upstream project.
- Third-party services we integrate with (Meta, LinkedIn, Google, Microsoft 365). Please report to those platforms directly.
- Denial-of-service and volumetric attacks. Do not test these against our infrastructure.
- Social engineering targeting our staff, contractors, or clients.
- Physical security of our offices or hardware.
- Findings that require a compromised end-user device, existing account access, or a network-position attack we do not control.
- Missing security headers or best-practice deviations with no demonstrated exploit path.
- Spam or phishing directed at Thrive Creative accounts (report to your own mail provider).
How to report
Email security@thrivecreative.ltd with:
- A clear description of the vulnerability
- Steps to reproduce (URLs, requests, screenshots, proof-of-concept)
- Impact — what an attacker could achieve
- Your preferred contact method for follow-up
- If you would like credit in our acknowledgments, the name or handle you’d like used
What to expect from us
- Acknowledgment within 3 business days confirming we’ve received your report.
- Initial triage within 7 business days.
- Regular status updates while we investigate and remediate.
- Coordinated public disclosure after the issue is fixed, typically within 90 days of initial report. We’re happy to extend for complex issues, or shorten if the risk is already public and unpatched.
Safe harbor
Thrive Creative will not pursue legal action against researchers who:
- Report vulnerabilities in good faith,
- Follow this policy — including no destruction of data, no service disruption, and no exfiltration of user data beyond the minimum needed to demonstrate impact,
- Give us reasonable time to remediate before public disclosure, and
- Do not attempt to phish, socially engineer, or otherwise involve our staff or clients in testing.
Researchers who follow this policy are considered authorized to conduct their testing under the terms of this policy, and we will not pursue civil action or refer good-faith research to law enforcement.
Credit
We’re happy to publicly acknowledge researchers who report valid issues in good faith. Let us know your preferred name or handle when you report, and whether you’d like a link to your website or social profile.
