Scope
This policy applies to publicly accessible EMT919 and City919 websites and systems that expressly link to it. Production customer environments, third-party systems, employee systems, physical locations, and social-engineering targets are outside scope unless authorized in writing.
Good-faith rules
A researcher must avoid privacy violations, service disruption, persistence, malware, data destruction, and access to non-public records. Stop testing immediately if non-public data is encountered or availability could be affected.
Prohibited without written authorization
- Denial-of-service, load, or destructive testing
- Credential stuffing, phishing, or social engineering
- Data exfiltration, extortion, or persistence
- Testing third-party providers or government customer systems
- Interfering with emergency or public-safety operations
- Public disclosure before a coordinated remediation date
How to report
Email security@city919.com with the affected system, a description, reproducible steps, potential impact, and safe proof of concept. Do not include customer records or sensitive case information.
Response
Fast Dial will endeavor to acknowledge a report within five business days, evaluate severity, investigate reproducibility, and provide updates when appropriate. Timing depends on severity, complexity, third-party involvement, and customer impact.
Safe harbor
Fast Dial does not intend to pursue legal action against researchers who comply with this policy, act in good faith, avoid harm, and report responsibly. This safe harbor does not apply to unlawful conduct, privacy violations, extortion, data theft, or activity outside the stated scope.
No bounty promise
This policy does not create a bug-bounty program or an obligation to pay rewards.