Responsible Disclosure Policy

Infinite Outdoors — Effective 2 September 2026. Version 1.0.

We take the security of our members, landowner partners, and systems seriously. If you find a vulnerability in an Infinite Outdoors product or service, we want to hear from you privately so we can fix it before it is misused.

How to report

Email engineering@infiniteoutdoorsusa.com. Do not post the issue publicly, open a public GitHub issue, or contact members or landowners about it.

Include:

  • The type of issue (for example cross-site scripting, broken access control, or exposed credentials)
  • The product, URL, or app version
  • The potential impact (what data or function an attacker could reach)
  • Step-by-step reproduction
  • Proof of concept only as far as needed to show the issue

We will acknowledge receipt within three business days and tell you when a fix is available.

In scope

  • infiniteoutdoorsusa.com and the production booking application
  • The Infinite Outdoors iOS app
  • Public APIs that serve that application
  • Related production sites we operate: infiniteoutdoorsdev.com, accessgrantedinitiative.com, io-mt-bma.com

Out of scope

  • Missing security headers, cookie flags, or CSP on their own
  • Clickjacking on pages with no sensitive action
  • Stack traces or version banners with no exploit path
  • Denial of service, volumetric flooding, or brute-force password spraying
  • Social engineering of staff, members, or landowners
  • Physical access to properties, offices, or devices
  • Third-party products we do not operate (payment processors, maps, analytics, conservation partners)
  • Findings from automated scanners that have not been confirmed by a person

Rules of engagement

  • Use your own test account. Do not access another member's or landowner's data.
  • Stop if you reach data that is not yours. Report what you saw; do not exfiltrate it.
  • Do not modify or delete data, and do not persist a foothold.
  • Do not test in a way that degrades the service for real users.

Safe harbor

If you follow this policy in good faith, Infinite Outdoors will not bring a claim against you under the Computer Fraud and Abuse Act, the DMCA anti-circumvention rules, or our Terms of Use for that research. You must still follow applicable law. If you are unsure whether a test is allowed, email first and wait for a reply.

Disclosure

Keep the report private until we have shipped a fix, or until we agree in writing that you may publish. We may describe the issue publicly after it is fixed. This is not a bug bounty. We do not pay for reports.

Contact

Security reports: engineering@infiniteoutdoorsusa.com