G-315Legal
Vulnerability Disclosure Policy
In plain words. If you find a security problem in DimSum Takeoff or our online services, email security@planbaseestimating.com. Test only against your own accounts and computers, don’t touch other people’s data, don’t knock anything over, and give us time to fix it before you tell anyone. If you follow these rules, we will treat your research as authorized, we won’t take legal action against you, and we’ll thank you publicly if you’d like. We aim to acknowledge reports within 3 business days. We don’t pay bug bounties at this time.
1. Who we are and why this policy exists
1.1 “Planbase”, “we” and “us” mean Planbase Estimating LLC, a Missouri limited liability company based in Kansas City, Missouri, USA. We make DimSum Takeoff, a desktop framing takeoff and estimating application, and run the online services listed in section 3.
1.2 Our customers trust us with their plans, prices and bids. We welcome reports from security researchers, customers and anyone else who finds a weakness, and we will work with you to fix it.
1.3 We are a small company. The commitments in section 7 are goals we work hard to meet, not contractual service levels.
2. How to report
2.1 Email: security@planbaseestimating.com
2.2 Encryption. If you need to send something sensitive, ask in your first email and we’ll arrange an encrypted channel.
2.3 Please include:
- (a) what you found and where (the URL, host, API endpoint, or the DimSum version and update channel, from Settings → About / Updates);
- (b) step-by-step instructions to reproduce it, and any proof-of-concept code or screenshots;
- (c) the impact as you see it, and what an attacker could do with it;
- (d) your operating system and browser, where relevant;
- (e) whether, and how, you would like to be credited; and
- (f) any date by which you plan to publish.
2.4 Language. We prefer reports in English.
2.5 Do not put details of an unfixed vulnerability in a public place (a forum, a review, social media, a public code repository or a support ticket anyone else can see).
2.6 Not a security issue? For help with your account or DimSum, write to support@planbaseestimating.com. If you think your own account has been taken over, write to support@ and security@ together. To report spam, malware or other abuse of our services, email misuse@planbaseestimating.com (see the Acceptable Use Policy).
3. Scope
3.1 In scope:
- (a) Websites and services:
planbaseestimating.comandwww.planbaseestimating.com,docs.planbaseestimating.com,app.planbaseestimating.com(the customer portal),api.planbaseestimating.comandupdates.planbaseestimating.com; - (b) DimSum Takeoff for Windows: the current Stable and Beta versions, their installers, and the auto-update process;
- (c) sign-in, licensing and activation: how DimSum and the portal handle sessions, license checks, the trial, seats and machine limits;
- (d) account-bound file protection: the encryption and sharing of DimSum files (
.dsum,.tsum,.bsumand the other*.sumfiles); - (e) DimSum Cloud (sync and storage) and the Remote Workstation (pairing, signalling and session security), once each is released; and
- (f) our emails: for example, flaws in our unsubscribe or email-confirmation links.
3.2 Out of scope (please don’t test or report these, unless you can show a real security impact on our customers):
- (a) other companies’ services we use, such as Cloudflare, Clerk, Paddle, Keygen, Resend, Sentry and Google. Report flaws in those to the company concerned. A misconfiguration of those services on our side is in scope;
- (b) social engineering of our staff, customers or providers, phishing, and physical attacks on offices, computers or people;
- (c) denial of service, load testing, or anything that degrades the service for others;
- (d) reports from automated scanners without a working proof of concept;
- (e) missing “best practice” settings without a demonstrated attack, such as a missing security header, cookie flag or email-authentication record on a domain that sends no mail;
- (f) clickjacking on pages with no sensitive action, self-XSS, logout or login CSRF, and open redirects without further impact;
- (g) rate limits on non-sensitive actions;
- (h) attacks that need an already-compromised computer, administrator rights on the victim’s computer, physical access to an unlocked computer, or an outdated, unsupported browser or operating system;
- (i) version banners and software versions, without a working exploit;
- (j) older DimSum versions that are no longer supported, if the issue is fixed in the current version.
3.3 License and file-protection bypasses. Ways to defeat the trial, seat or machine limits, the trial watermark, or account-bound file protection are in scope to report. Do not publish, share or sell a working bypass, crack or key generator, before or after we fix it.
4. Rules for testing
To stay within this policy, you must:
- (a) use only your own accounts and data. Start a free trial, or create test accounts and Workspaces with addresses you control. You may test interactions between accounts only if you control all of them;
- (b) stop and tell us if you reach anyone else’s data (personal data, files, prices, plans or bids). Access only the minimum needed to show the problem, don’t copy, keep or share it, and delete anything you obtained once you’ve reported it;
- (c) not disrupt the service. No denial of service, no flooding, no spam. Keep automated testing to a gentle rate: no more than 5 requests per second to any host;
- (d) not leave anything behind. No backdoors, persistent accounts or malicious files; clean up test data when you’re done;
- (e) use the Remote Workstation only with computers you own and control at both ends;
- (f) not make real purchases with stolen or test payment details, or try to defraud our payment provider. Payment flows run through Paddle; report problems with our integration, but don’t attack Paddle itself;
- (g) not demand payment or anything else in exchange for not disclosing a vulnerability;
- (h) follow the law, apart from the activities this policy authorizes; and
- (i) give us reasonable time to fix the issue before you disclose it (section 8).
5. Safe harbour
5.1 If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we consider your research authorized, and:
- (a) under the US Computer Fraud and Abuse Act and comparable state laws (including Missouri’s computer-tampering laws, RSMo §§ 569.095–569.099), we will not pursue or support any civil action or law-enforcement complaint against you for accidental, good-faith violations of this policy;
- (b) under the anti-circumvention rules of the DMCA (17 U.S.C. § 1201), we will not bring a claim against you for circumventing technological measures in DimSum, to the extent needed for research within this policy;
- (c) we waive the restrictions in our Terms of Service, EULA and Acceptable Use Policy on reverse engineering, probing, testing and circumventing security, only to the limited extent needed to research and report under this policy, and only for that research; and
- (d) if a third party brings legal action against you over research that followed this policy, we will make it known that your activities were authorized by us.
5.2 Limits. We can authorize research only on systems and software we own or control. We cannot authorize testing of other companies’ systems (section 3.2(a)), and this policy doesn’t bind any other party. It does not authorize activity outside its rules, or any activity that is unlawful for reasons other than the computer-access and anti-circumvention laws above.
5.3 When in doubt, ask. If you’re unsure whether something is allowed, email security@planbaseestimating.com before you go further.
6. Our use of what you send
6.1 We use your report to investigate and fix the problem. We may share it with service providers who need it to help us, and with affected customers or authorities where the law requires.
6.2 We don’t share your name or contact details without your permission, except where the law requires.
6.3 By sending a report, you agree that we may use it to fix our products and services without owing you any payment or obligation, except as this policy says.
7. What we commit to
These are goals for a small team, measured in business days (Monday to Friday, US Central Time, excluding US federal holidays).
| Step | Our goal |
|---|---|
| Acknowledge your report | Within 3 business days |
| Initial assessment (is it valid, and how serious) | Within 10 business days |
| Progress updates | At least every 14 days until it’s fixed, or sooner when something changes |
| Fix, by severity (we use CVSS v4.0 as a guide) | Critical: as fast as we can, aiming for 7 days. High: 30 days. Medium: 90 days. Low: in a normal release |
| Tell you when it’s fixed | When the fix is released, so you can check it |
7.1 How DimSum fixes reach customers. We ship fixes through DimSum’s auto-update. A fix for a serious security flaw may be marked critical, which customers must install, as the EULA explains. Fixes to our online services take effect when deployed.
7.2 If we can’t meet a goal, we’ll tell you why and give a new estimate.
7.3 If we disagree with your assessment, we’ll explain why. You’re welcome to send more information.
8. Coordinated disclosure
8.1 Please give us 90 days from your report, or until a fix is released if that’s sooner, before you disclose details publicly. If we need longer for a complex fix, we’ll ask, and explain why. If we stop responding, you may disclose after that period, giving us a few days’ notice.
8.2 We may publish a security advisory for issues that affect customers, in What’s new and in the release notes. We will credit you there if you’d like (section 9).
8.3 CVE identifiers. We are not a CVE Numbering Authority. Where an issue in DimSum warrants a CVE, we will request one, or support your request.
9. Thanks and bug bounty
9.1 Public thanks. With your permission, we’ll list your name or handle, and a link of your choice, on our acknowledgements page, planbaseestimating.com/legal/vulnerability-disclosure/#thanks, and in the release notes for the fix.
9.2 No bug bounty. We do not offer payment for vulnerability reports at this time. Any reward we choose to give is at our discretion, and doesn’t create an obligation to give others.
10. Changes to this policy
We may update this policy. The current version, with its “Last updated” date, is at https://planbaseestimating.com/legal/vulnerability-disclosure/. Research you started under an earlier version stays covered by that version’s safe harbour.
11. security.txt
We will publish a security.txt file (RFC 9116) so that researchers and automated tools can find this policy. It goes at https://planbaseestimating.com/.well-known/security.txt.
Publishing notes:
- Serve the same file over HTTPS at
/.well-known/security.txton every host in section 3.1(a). Make sureupdates.planbaseestimating.com, which asks for a license or beta key on other paths, serves this one path without any key. Expiresis required. Set it to no more than a year after publication; RFC 9116 recommends less than a year. We renew the file each year, with a reminder 1 month before itsExpiresdate.- Add an
Encryption:line if a PGP key is published (section 2.2). Optionally sign the file with that key (an OpenPGP cleartext signature). PolicyandAcknowledgmentsmust point to the published URL of this policy, under/legal/<name>/as below.- The
#lines are comments, and are allowed in the file.
# security.txt for Planbase Estimating LLC (DimSum Takeoff)
# Report security issues to the address below. Please read our policy first.
# Our policy: no testing of other customers' data, no denial of service,
# coordinated disclosure. Safe harbour for good-faith research is in the policy.
# Spam, abuse or misuse of our services (not vulnerabilities): misuse@planbaseestimating.com
Contact: mailto:security@planbaseestimating.com
Expires: 2027-09-30T23:00:00.000Z
Preferred-Languages: en
Policy: https://planbaseestimating.com/legal/vulnerability-disclosure/
Acknowledgments: https://planbaseestimating.com/legal/vulnerability-disclosure/#thanks
Canonical: https://planbaseestimating.com/.well-known/security.txt
Canonical: https://www.planbaseestimating.com/.well-known/security.txt
Canonical: https://docs.planbaseestimating.com/.well-known/security.txt
Canonical: https://app.planbaseestimating.com/.well-known/security.txt
Canonical: https://api.planbaseestimating.com/.well-known/security.txt
Canonical: https://updates.planbaseestimating.com/.well-known/security.txt
The Expires value above is an example for publication in October 2026. Change it to match the real publication date.
Planbase Estimating LLC, 3418 East 104th Street, Kansas City, MO 64137, USA. Questions: legal@planbaseestimating.com.All legal documents.