Scapia's responsible disclosure policy
How to report an issue?
If you happen to have identified a vulnerability on any of our web properties, we request you to follow the steps outlined below:
Please contact us immediately by sending an email to firstname.lastname@example.org with the necessary details to recreate the vulnerability scenario. This may include screenshots, videos or simple text instructions.
If possible, share with us your contact details (email, phone number), so that our security team can reach out to you if further inputs are needed to identify or close the problem.
If you intend to make the information public for educational or other such needs, please give us reasonable time to appropriately fix the problem before making such information public. Our security team will work with you to estimate and commit to such time frame.
If the identified vulnerability can be used to potentially extract information of our customers or systems, or impair our systems' ability to function normally, then please refrain from actually exploiting such a vulnerability. This is absolutely necessary for us to consider your disclosure a responsible one. While we appreciate the inputs of Whitehat hackers, we may take legal recourse if the identified vulnerabilities are exploited for unlawful gains or getting access to restricted customer or system information or impairing our systems.
We do not have a bounty/cash reward program for such disclosures, but we express our gratitude for your contribution in different ways. For genuine ethical disclosures, we would be glad to publicly acknowledge your contribution in this section on our website. Of course, this will be done only if you want a public acknowledgement. Notwithstanding anything contained herein, you hereby acknowledge and agree that any acknowledgement of your contribution provided herein does not and is not intended to mean that Scapia shall pay or is liable to pay any compensation for any loss or damage caused to you or any other person. You hereby understand and agree that to the extent allowed under applicable laws, Scapia disclaims all liability arising from your usage of the Scapia website or mobile application