Security researchers play an important role in keeping Stoatify safe. If you believe you have found a vulnerability in a Stoatify product or service, please report it to us as soon as possible. We will investigate, keep you informed, and work to remediate confirmed issues.
How to report a vulnerability
Email security@stoatify.com. Please do not include sensitive data in the subject line. Include as much of the following as you can:
- The affected product, hostname, endpoint, mobile app, or feature;
- A clear description of the vulnerability and its potential impact;
- Steps to reproduce the issue, including proof-of-concept code or screenshots when useful;
- The date and time of your testing and any request or account identifiers that can help us investigate;
- Whether you accessed any data unintentionally and what you did with it; and
- Your preferred name and contact details if you want recognition or follow-up.
For ordinary support requests, account access problems, suspected fraud, or privacy questions that do not involve a product vulnerability, contact support@stoatify.com.
What to expect from us
After you send a report to our security address, we aim to:
- Acknowledge receipt within two business days;
- Provide an initial assessment within five business days;
- Send a status update at least every ten business days while a confirmed issue remains open; and
- Tell you when the issue is remediated or otherwise resolved.
These are response targets, not guarantees. Complex reports can take longer to reproduce or remediate. We prioritize confirmed vulnerabilities based on severity, exploitability, and potential impact, and we may ask you for additional information during the investigation.
Testing scope
This policy covers the following Stoatify-owned products and services:
- Stoatify web services at
www.stoatify.com,app.stoatify.com,api.stoatify.com,support.stoatify.com,trust.stoatify.com, andstatus.stoatify.com; - Other publicly accessible services on a domain owned and operated by Stoatify; and
- Official Stoatify applications distributed for iOS and Android.
A security issue in Stoatify's use or configuration of a third-party service is in scope. The third-party service itself is not. If you are unsure whether a target is in scope, email us before testing it.
Research guidelines
To qualify as good-faith research under this policy, you must:
- Test only accounts and data you own or have explicit permission to use;
- Make a reasonable effort to avoid privacy violations, data loss, service disruption, and degraded performance;
- Use the minimum access and amount of data necessary to demonstrate the issue;
- Stop testing and report immediately if you encounter personal data, document contents, credentials, or other confidential information;
- Delete any Stoatify data obtained during research as soon as the report is submitted;
- Do not retain persistence, pivot to other systems, or use a vulnerability beyond what is needed to confirm it; and
- Comply with applicable law and the coordinated disclosure terms below.
Out of scope and prohibited testing
The following activities are not authorized under this policy:
- Denial-of-service, load, stress, or other availability testing;
- High-volume automated scanning or testing that bypasses or triggers rate limits;
- Social engineering, phishing, impersonation, or physical attacks;
- Malware delivery, persistence, destructive testing, or intentional data modification or deletion;
- Accessing, downloading, or changing another person's or organization's data;
- Testing third-party providers, applications, websites, or infrastructure that Stoatify does not control;
- Testing on behalf of a sanctioned entity or in violation of applicable export-control laws; and
- Public disclosure that does not follow the coordinated disclosure terms below.
Reports that only identify missing security headers, self-XSS, clickjacking without a sensitive action, rate limiting without a demonstrated security impact, software version disclosure, or scanner output without a reproducible impact may not be treated as vulnerabilities.
Safe harbor
When you conduct research in good faith and follow this policy, Stoatify considers that research to be:
- Authorized under applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
- Authorized under applicable anti-circumvention laws, and we will not bring a claim against you for circumventing technological controls as part of research permitted by this policy;
- Exempt, on a limited basis, from provisions in our Terms of Service that would prevent the security research permitted by this policy; and
- Helpful to the security of Stoatify, our users, and the wider internet.
If a third party starts legal action against you and you have complied with this policy, we will take reasonable steps to make it known that your research followed this policy. This safe harbor applies only to legal claims controlled by Stoatify. It does not bind independent third parties, and it does not authorize conduct that violates applicable law.
If you are uncertain whether your planned research follows this policy, contact us before continuing. We will make a good-faith effort to clarify the policy and, where appropriate, provide written authorization.
Coordinated disclosure
Please keep vulnerability details confidential until we confirm remediation or 90 calendar days have passed since we acknowledged your report, whichever comes first. We may ask you to delay disclosure when exceptional circumstances make more time necessary to protect users. Any extension must be agreed with you in writing. We welcome advance coordination on the content and timing of any publication.
Recognition and rewards
This is a vulnerability disclosure program, not a bug bounty program. Stoatify does not promise payment or other rewards. We may recognize researchers who report valid vulnerabilities if they ask to be named and disclosure is safe after remediation.
Questions
Questions about this policy or the scope of planned research can be sent to security@stoatify.com.