1.How we protect data
- 1.1Authorization is enforced at the database layer with row-level security, so a defect in application code cannot by itself expose another member's record.
- 1.2Role checks are evaluated server-side against the authenticated session; clients cannot assert their own role.
- 1.3Passwords are stored only as salted one-way hashes; TOTP two-factor authentication is available now and mandatory from January 1, 2027.
- 1.4Card data is handled exclusively inside our PCI DSS Level 1 payment provider's hosted fields and never reaches Society systems.
- 1.5Uploaded documents and member photographs are held in private storage and served only through short-lived signed URLs.
- 1.6Privileged actions in the executive portal are recorded in an append-only audit log with actor, timestamp and affected membership number.
2.Reporting a vulnerability
- 2.1Email security@americancomputersociety.com with a clear description, affected URL or endpoint, and reproduction steps. A machine-readable contact is published at /.well-known/security.txt.
- 2.2We acknowledge within 3 business days, give an initial assessment within 10 business days, and keep you updated until the issue is resolved.
- 2.3Our target remediation is 7 days for critical, 30 days for high and 90 days for medium and low severity findings.
- 2.4We support coordinated disclosure and will agree a publication date with you, normally 90 days from report or on fix, whichever is sooner. We are glad to credit you by name in our advisory.
3.Safe harbor
- 3.1If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you, and we will make that position known if a third party does.
- 3.2Stay within scope: americancomputersociety.com and its subdomains. Out of scope are our payment provider's and print partner's own systems, and any third-party service we merely link to.
- 3.3Use only accounts you own or have permission to test. Stop at proof of concept, do not access, modify or exfiltrate other members' data, and delete any incidental data you encounter.
- 3.4No denial of service, no social engineering of staff or members, no physical attacks, and no automated scanning that degrades service for others.
- 3.5We do not currently operate a paid bug bounty; recognition is offered in our hall of thanks.
4.Breach notification
If a breach is likely to result in risk to members, we notify affected members without undue delay and in any event within 72 hours of becoming aware, together with any regulator required by applicable state law, and publish a factual post-incident note describing cause, impact and corrective action.
Questions about this policy?
Write to the Office of the Corporate Secretary, American Computer Society, 600 Congress Avenue, Suite 1400, Austin, Texas 78701.
Contact the Society →