1. Reporting
Email security@deepacal.com with a clear description, reproduction steps, affected endpoints and impact assessment. Please allow up to ninety (90) days for remediation before any public disclosure, and coordinate disclosure with us.
2. Permitted testing
- Test only against your own account and your own data.
- Stop as soon as you confirm a vulnerability; do not pivot, escalate or exfiltrate.
- No denial-of-service, load or spam testing, no social engineering of staff or users, and no physical attacks.
- Never access, modify, publish or retain another user's personal data, media or biometric content.
3. Safe harbour
Research conducted in good faith and in compliance with this Policy will not be pursued by Deepacal as a violation of our Terms or as unlawful access. We will make this position known if a third party raises a claim regarding conduct within this Policy.
4. Rewards
We do not operate a paid bounty programme at this time. We acknowledge valid reports and, at our discretion, may offer credits or public recognition.