Our Commitment to Security
At veycet, we consider the security of our systems and our clients' data a top priority. Despite our best efforts, vulnerabilities may still exist. We value the role that security researchers and the wider community play in helping to keep our systems secure.
Reporting Vulnerabilities
If you discover a vulnerability, we would appreciate your help in disclosing it to us in a responsible manner. Please act in good faith and follow these guidelines:
- Submit your findings to info@bycet.com
- Provide sufficient information to reproduce the vulnerability
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
- Do not access, modify, or destroy data that does not belong to you
- Give us a reasonable time to address the vulnerability before public disclosure
- Do not use attacks on physical security, social engineering, or DDoS attacks
What We Promise
In return for your responsible disclosure, we commit to:
- Respond to your report within 3 business days with our assessment
- Work diligently to resolve confirmed vulnerabilities in a timely manner
- Keep you informed of our progress throughout the remediation process
- Credit you as the discoverer (unless you prefer to remain anonymous)
- Not take legal action against you provided you follow this policy
Out of Scope Vulnerabilities
The following issues are generally considered out of scope:
- Clickjacking on pages with no sensitive actions
- Missing security headers that don't lead directly to a vulnerability
- Theoretical vulnerabilities without practical exploitability
- Denial of service attacks
- Social engineering or physical security attacks
- Vulnerabilities in third-party applications that we use
Safe Harbor
We will not initiate legal action against security researchers who discover and report vulnerabilities through this responsible disclosure process, provided they:
- Follow the guidelines outlined in this policy
- Do not violate any laws or compromise data privacy
- Act in good faith to avoid privacy violations and service disruption
- Do not use the vulnerability for personal gain beyond potential recognition
Recognition
With your permission, we would like to credit your responsible disclosure in our Security Hall of Fame. Please let us know if you prefer to remain anonymous.
Contact Information
Please send all vulnerability reports to:
Email: info@bycet.com
We prefer encrypted communications. Please use our PGP key if possible.
Thank You
We appreciate your efforts to make Veycet and the internet a safer place. Your expertise and ethical approach help us maintain the highest security standards for our clients and their users.