1. Contact¶
If you have discovered a security vulnerability in our systems or on our website, please contact us:
- Email: [email protected]
- Alternatively: [email protected]
2. Rules¶
- Do not access other users’ data
- Do not perform destructive actions (DoS, data deletion)
- Do not share the vulnerability publicly before it is fixed
- Give us reasonable time to fix the issue (minimum 90 days)
3. What to Report¶
- XSS, SQL injection, CSRF
- Authentication/authorization bypass
- Sensitive data leaks
- Misconfiguration
4. What Not to Report¶
- Results of automated scanners without verification
- Social engineering / phishing
- Denial of Service
5. Reward¶
We currently do not have a formal bug bounty programme, but we appreciate and value every responsible disclosure.