EST · A Nant Global Finance Company · New York, NY
Security

Vulnerability Disclosure Policy.

Effective date: August 18, 2026

Jump to a section
  1. 1. Our Commitment
  2. 2. Scope
  3. 3. How to Report
  4. 4. What You Can Expect from Us
  5. 5. Safe Harbor
  6. 6. Ground Rules
  7. 7. Out of Scope
  8. 8. Questions

1. Our Commitment

Equity Stock Transfer, LLC ("EST") operates capital markets infrastructure, and we take the security of our systems and of shareholder information seriously. We value the work of good-faith security researchers and welcome reports of potential vulnerabilities so we can investigate and remediate them quickly.

2. Scope

This policy covers systems operated by EST or on its behalf, including:

  • www.equitystock.com (this website); and
  • my.equitystock.com and other portals branded and operated by EST.

Some EST portals run on software platforms operated by third-party providers. Do not test third-party infrastructure without that provider’s authorization; where a finding relates to a third-party platform, report it to us and we will coordinate with the provider.

3. How to Report

Email security@equitystock.com with:

  • a description of the vulnerability and its potential impact;
  • steps to reproduce (proof-of-concept where possible);
  • the URL, endpoint, or system affected, and the date/time of testing; and
  • your contact information for follow-up.

4. What You Can Expect from Us

  • Acknowledgment of your report within two business days;
  • A good-faith assessment and updates on the status of validated findings;
  • Credit, if you wish, once a validated issue is remediated — we do not currently operate a paid bounty program.

5. Safe Harbor

For security research conducted in good faith and in compliance with this policy, EST will not initiate legal action against you and will consider your research authorized under applicable anti-hacking and anti-circumvention laws. If a third party initiates legal action against you for activity conducted in compliance with this policy, we will make it known that your actions were authorized.

6. Ground Rules

To remain within this policy, you must:

  • test only accounts you own or are expressly authorized to use;
  • stop and report immediately upon encountering personal or shareholder information — do not access, copy, or retain more data than the minimum needed to demonstrate the issue;
  • not disrupt services, degrade performance, or destroy data (no denial-of-service testing);
  • not use social engineering, phishing, or physical attacks against EST, its employees, or its facilities;
  • not publicly disclose a vulnerability before we have had a reasonable opportunity to remediate it, and not disclose it to third parties without our written permission; and
  • comply with all applicable laws.

7. Out of Scope

  • Findings without demonstrable security impact (for example, missing best-practice headers alone, clickjacking on pages with no sensitive actions, or software version disclosure without an exploitable path);
  • Denial-of-service, spam, or resource-exhaustion issues;
  • Reports from automated scanners without validation;
  • Third-party services outside EST’s control (report these to the relevant vendor).

8. Questions

Questions about this policy: security@equitystock.com.