Responsible Disclosure Policy

We take the security of our platform and user data seriously. We appreciate the work of security researchers who help us keep our platform safe, and we encourage the responsible reporting of any potential vulnerabilities.

Guidelines for Responsible Reporting

If you believe you have discovered a vulnerability on our platform, please follow these guidelines to disclose it responsibly:

  1. Private Disclosure: Share the details of the vulnerability privately with us first. Do not disclose, discuss, or publish information about the vulnerability publicly or with third parties until we have had a reasonable amount of time to investigate and address the issue.
  2. Good-Faith Engagement: Avoid violating user privacy, destroying data, or disrupting our services. Engage only with accounts and data that you own or have explicit authorization to test.
  3. Report Quality: Provide a clear, detailed, and actionable description of the issue including URLs, steps to reproduce, and impact.
  4. No Malicious Activity: Do not exploit the vulnerability beyond what is strictly necessary to prove its existence.
Important Notice: While we appreciate and value good-faith security reports, our platform does not currently offer a bug bounty program or financial rewards for vulnerability disclosures.

How to Submit

Please compile your findings and send them directly to our security and legal desk:

legal@example.com

Our Commitment

  • Acknowledgment: We aim to acknowledge receipt of your report as soon as reasonably possible.
  • Investigation: We review and prioritize reports according to severity and potential impact.
  • Resolution: We work diligently to remediate confirmed vulnerabilities.