At Bomdiu, we take security seriously and value the contributions of security researchers and the broader security community in helping us maintain the safety and integrity of our systems. This Vulnerability Disclosure Policy outlines the guidelines for reporting security vulnerabilities to us.
This policy applies to any security vulnerabilities found in Bomdiu’s publicly accessible services, including our website, APIs, and any other systems owned and operated by Bomdiu.
The following are considered out of scope for this policy:
We request that security researchers adhere to the following guidelines when reporting vulnerabilities:
If you have discovered a security vulnerability, please report it to us via security@bomdiu.com with the following details:
We aim to acknowledge receipt of your report within 2 business days and provide an initial assessment within 5 business days. We will keep you informed of our progress as we investigate and remediate the issue.
Once you have submitted a report, we are committed to the following:
Bomdiu does not offer financial rewards or compensation for security vulnerability disclosures. However, we deeply value the contributions of security researchers. We may offer public acknowledgement for significant and responsibly disclosed vulnerabilities, with your permission.
By submitting a report, you agree to avoid any unlawful activities and follow ethical disclosure practices. Bomdiu will not take legal action against researchers who act in good faith and comply with this policy.
We appreciate the efforts of security researchers in making Bomdiu’s services more secure. If you have any questions about this policy, please contact us at security@bomdiu.com.
Thank you for helping us maintain the security of our systems.