Responsible Disclosure Policy
Infinite Outdoors — Effective 2 September 2026. Version 1.0.
We take the security of our members, landowner partners, and systems seriously. If you find a vulnerability in an Infinite Outdoors product or service, we want to hear from you privately so we can fix it before it is misused.
How to report
Email engineering@infiniteoutdoorsusa.com. Do not post the issue publicly, open a public GitHub issue, or contact members or landowners about it.
Include:
- The type of issue (for example cross-site scripting, broken access control, or exposed credentials)
- The product, URL, or app version
- The potential impact (what data or function an attacker could reach)
- Step-by-step reproduction
- Proof of concept only as far as needed to show the issue
We will acknowledge receipt within three business days and tell you when a fix is available.
In scope
- infiniteoutdoorsusa.com and the production booking application
- The Infinite Outdoors iOS app
- Public APIs that serve that application
- Related production sites we operate: infiniteoutdoorsdev.com, accessgrantedinitiative.com, io-mt-bma.com
Out of scope
- Missing security headers, cookie flags, or CSP on their own
- Clickjacking on pages with no sensitive action
- Stack traces or version banners with no exploit path
- Denial of service, volumetric flooding, or brute-force password spraying
- Social engineering of staff, members, or landowners
- Physical access to properties, offices, or devices
- Third-party products we do not operate (payment processors, maps, analytics, conservation partners)
- Findings from automated scanners that have not been confirmed by a person
Rules of engagement
- Use your own test account. Do not access another member's or landowner's data.
- Stop if you reach data that is not yours. Report what you saw; do not exfiltrate it.
- Do not modify or delete data, and do not persist a foothold.
- Do not test in a way that degrades the service for real users.
Safe harbor
If you follow this policy in good faith, Infinite Outdoors will not bring a claim against you under the Computer Fraud and Abuse Act, the DMCA anti-circumvention rules, or our Terms of Use for that research. You must still follow applicable law. If you are unsure whether a test is allowed, email first and wait for a reply.
Disclosure
Keep the report private until we have shipped a fix, or until we agree in writing that you may publish. We may describe the issue publicly after it is fixed. This is not a bug bounty. We do not pay for reports.
Contact
Security reports: engineering@infiniteoutdoorsusa.com