Responsible Disclosure
Версія: 0.9 (draft) · Оновлено: 2026-09-11
Документ ведеться англійською; юридичну силу має англійський текст.
1. We want the report
Found a vulnerability in a Baynoy system? Tell us before anyone else. Write to [email protected] with steps to reproduce, affected addresses, and impact as you see it. Encrypted mail preferred; we acknowledge within 2 business days.
2. Safe harbor
If you research in good faith — no data exfiltration beyond a minimal proof, no service disruption, no social engineering of staff or customers, no lateral movement into accounts that are not yours — we will not pursue legal action for the research itself and we will work with you, not against you.
3. Scope
In scope: baynoy.com and its subdomains, the APIs, and the mobile applications. Out of scope:
- Denial of service and volumetric testing.
- Findings requiring stolen credentials or physical access.
- Third-party services we merely link to.
- Reports from automated scanners without a demonstrated impact.
4. What we do with it
We triage, confirm, and fix on a severity-based timeline, and we tell you when it is fixed. We do not run a paid bounty program yet; when that changes, this page will say so first — we promise credit (if you want it) and honesty about timelines meanwhile.