Bug Bounty Program - Reporting Security Vulnerabilities

At Alorica we want to provide our customers with technology and services that deliver Tech-enabled experiences across every touch point. We want to do that in a way that protects our customers and partners from the wide variety of cyber security threats that exist.

With that in mind Alorica Inc. invites security professionals from all backgrounds to assess our public facing defenses with an objective & professional eye in order to discover potential vulnerabilities and help us to continually improve the security of our platform.

Our public bug bounty program is managed through BugCrowd. Please report any security vulnerabilities through our BugCrowd page. The bug bounty program and its rewards are applicable only to security vulnerabilities. Bug bounty rewards are reviewed on a case-by-case basis and not all disclosures may result in a payout (e.g., duplicate disclosures, incomplete disclosure of TTP, etc.). If your risk disclosure is deemed eligible for a payout, you will receive an email invitation requiring you to resubmit the finding into a Bug Bounty Reward Program. Afterwards, KYC (know your customer) will be conducted before the payout is issued.



Ethical Vulnerability Disclosure Policy

Introduction

At Alorica, we are committed to safeguarding the security and privacy of our systems, data, and services. Despite our best efforts, vulnerabilities may still exist. We welcome responsible security researchers and ethical hackers to report potential vulnerabilities in a lawful and ethical manner.

This policy outlines how to report security issues and the conditions under which we engage with disclosures.

Scope

This policy applies only to:

  • Publicly accessible systems and services hosted on the alorica.com domain

This policy does not apply to:

  • Social engineering attacks (e.g., phishing, vishing)
  • Physical security vulnerabilities
  • Third-party services not under Alorica’s control

Guidelines for Responsible Disclosure

  • Act in good faith and avoid privacy violations, service disruption, or data destruction
  • Do not access, modify, store, or delete data without authorization
  • Avoid using automated tools that generate excessive traffic or system load
  • Provide sufficient detail for Alorica to verify and reproduce the vulnerability
  • Do not publicly disclose any vulnerability without Alorica’s written consent
  • Follow all applicable laws and avoid actions that could cause harm

How to Report a Vulnerability

To report a potential security vulnerability, please submit the finding using the following submission link: https://bugcrowd.com/engagements/alorica-vdp-pro

Include the following details in your report:

  • A concise and clear description of the vulnerability
  • Step-by-step instructions or proof-of-concept code
  • The affected system or URL
  • The potential impact of the issue
  • Your contact information (optional)

Alorica’s Commitment

If you report a vulnerability in accordance with this policy, Alorica commits to:

  • Acknowledge receipt within 5 business days
  • Work with you to resolve issues
  • Treat reports as confidential
  • No legal action for good-faith reporting

Exclusions and Non-Compliance

The following actions fall outside the scope of this policy and may be subject to legal action:

  • Unauthorized data access or exfiltration
  • Use of vulnerabilities to compromise, extort, or disrupt services
  • Disclosure without coordination

Safe Harbor

If your actions are lawful and follow this policy in good faith:

  • Good faith actions are considered authorized
  • No legal action for compliant reports

Last updated: July 22, 2025

For more information, please visit alorica.com/contact