Bozza — in revisione legale. Questo documento non è ancora in vigore.

Note legali

Responsible Disclosure

Versione: 0.9 (draft) · Ultimo aggiornamento: 2026-09-11

Questo documento è mantenuto in inglese; fa fede il testo inglese.

1. We want the report

Found a vulnerability in a Baynoy system? Tell us before anyone else. Write to [email protected] with steps to reproduce, affected addresses, and impact as you see it. Encrypted mail preferred; we acknowledge within 2 business days.

2. Safe harbor

If you research in good faith — no data exfiltration beyond a minimal proof, no service disruption, no social engineering of staff or customers, no lateral movement into accounts that are not yours — we will not pursue legal action for the research itself and we will work with you, not against you.

3. Scope

In scope: baynoy.com and its subdomains, the APIs, and the mobile applications. Out of scope:

  • Denial of service and volumetric testing.
  • Findings requiring stolen credentials or physical access.
  • Third-party services we merely link to.
  • Reports from automated scanners without a demonstrated impact.

4. What we do with it

We triage, confirm, and fix on a severity-based timeline, and we tell you when it is fixed. We do not run a paid bounty program yet; when that changes, this page will say so first — we promise credit (if you want it) and honesty about timelines meanwhile.