Responsible Disclosure Policy

We consider the security of our systems and our clients’ data a top priority. But no matter how much effort we put into security, vulnerabilities can still be present. If you discover one, we want to know about it so we can address it as quickly as possible. This policy explains how to report it to us, what we ask of you, and what you can expect from us in return.

Scope

In scope:

  • Billy Grace production web applications and APIs hosted under *.billygrace.com;
  • Billy Grace tracking endpoints, SDKs and publicly distributed client libraries;
  • Billy Grace-specific configurations and integrations that could expose Billy Grace or client data.

Out of scope:

  • Customer websites and applications;
  • Vulnerabilities in third-party products themselves (for example hosting, authentication or CRM providers). Billy Grace-specific misconfigurations remain in scope;
  • Any system not owned or operated by Billy Grace.

If you accidentally gain access to data belonging to one of our clients or to another user, stop immediately, do not view or download more than the minimum needed to establish the issue, report it to us, and securely delete any data you obtained.

Reporting

Please email reports to [email protected]. Include enough information for us to reproduce the issue, including affected URLs or endpoints, steps to reproduce, impact, and supporting evidence where appropriate. Anonymous reports are accepted, although this may limit our ability to follow up.

Rules of engagement

  • Do not take advantage of the vulnerability, for example by downloading, modifying, or deleting data beyond the minimum necessary to demonstrate the issue.
  • Treat all information about the vulnerability, your report, and our systems as confidential. Do not share it with anyone else, at any time, without our prior written consent (see “Confidentiality” below).
  • Do not use attacks on physical security, social engineering, (distributed) denial of service, spam, or brute-force attacks, and do not test applications of third parties.
  • Do not place a backdoor, make changes to the system, or repeatedly access the system to demonstrate the vulnerability. One careful demonstration is enough.
  • Avoid accessing or modifying customer data.
  • Use synthetic test data wherever possible.
  • Do not pivot from one affected system into another.
  • Do not retain customer data or include it unredacted in the report.
  • Do not send malware, persistent payloads or unsolicited files to employees.
  • Only use accounts you own or have explicit permission to use.

Out of scope reports

To keep our attention on issues that genuinely affect security, the following are out of scope unless you can demonstrate a concrete, exploitable impact:

  • Missing security headers or best-practice configurations without a demonstrated vulnerability (e.g. CSP, HSTS, X-Frame-Options on non-sensitive pages);
  • SPF, DKIM, or DMARC configuration issues;
  • Clickjacking on pages with no sensitive actions;
  • Software version disclosure, banner disclosure, or descriptive error messages;
  • Self-XSS or issues that require the victim to attack themselves;
  • Missing rate limiting without demonstrated impact;
  • Reports generated by automated scanners without validation or analysis;
  • Vulnerabilities requiring physical access to a user’s device;
  • Reports about our use (or non-use) of specific TLS cipher suites without a practical attack.

Our commitments

  • We will acknowledge your report within 5 business days and give you our initial assessment within 10 business days.
  • We will keep you informed of our progress towards resolving the problem.
  • If you have acted in good faith and in accordance with this policy, we consider your research authorised. We will not report you to law enforcement and will not pursue civil action against you in connection with your report. Note that we cannot bind the Public Prosecution Service; however, acting within this policy is a strong indication of good faith.
  • We will handle your report confidentially and will not share your personal details with third parties without your permission, unless we are legally required to do so.

Recognition and rewards

We may, at our discretion, thank reporters publicly or offer another form of recognition. In exceptional cases we may offer a financial reward. Whether we offer a reward, and its size, depends on the severity of the vulnerability and the quality of the report. A few ground rules:

  • Only the first reporter of a previously unknown vulnerability is eligible.
  • One reward per underlying vulnerability, even if it appears in multiple places.
  • Reports in the “out of scope” categories above, and unvalidated automated scanner output, are not eligible.
  • Eligibility for a reward is conditional on the vulnerability and your report remaining confidential, both before and after resolution.
  • There is no entitlement to a reward; this policy is not a bug bounty programme.

Confidentiality

All information relating to a reported vulnerability, including its existence, technical details, affected systems, and any data encountered during your research, must be treated as strictly confidential, both before and after the vulnerability has been resolved. Do not publish, present, or otherwise share this information with any third party without our prior written consent.

Client identities, client data, credentials, and commercially sensitive information must never be disclosed without explicit written permission.