Vulnerability disclosure

Report it responsibly.

Clear reporting instructions, authorized testing boundaries, and a good-faith safe harbor for security researchers.

Scope

This policy applies to publicly accessible EMT919 and City919 websites and systems that expressly link to it. Production customer environments, third-party systems, employee systems, physical locations, and social-engineering targets are outside scope unless authorized in writing.

Good-faith rules

A researcher must avoid privacy violations, service disruption, persistence, malware, data destruction, and access to non-public records. Stop testing immediately if non-public data is encountered or availability could be affected.

Prohibited without written authorization

How to report

Email security@city919.com with the affected system, a description, reproducible steps, potential impact, and safe proof of concept. Do not include customer records or sensitive case information.

Response

Fast Dial will endeavor to acknowledge a report within five business days, evaluate severity, investigate reproducibility, and provide updates when appropriate. Timing depends on severity, complexity, third-party involvement, and customer impact.

Safe harbor

Fast Dial does not intend to pursue legal action against researchers who comply with this policy, act in good faith, avoid harm, and report responsibly. This safe harbor does not apply to unlawful conduct, privacy violations, extortion, data theft, or activity outside the stated scope.

No bounty promise

This policy does not create a bug-bounty program or an obligation to pay rewards.