1. Scope
This policy covers:
- yanutek.com and its subdomains.
- Our publicly accessible web applications and APIs.
Out of scope:
- Third-party platforms, vendors, or sub-processors.
- Social-engineering attacks against employees, customers, or vendors; physical attacks; and any denial-of-service testing.
- Reports based solely on outdated software versions without a working proof of concept.
2. Rules of engagement
- Test only against accounts and data you own or have permission to access.
- Avoid privacy violations, data destruction, and service degradation.
- Do not exfiltrate data beyond the minimum needed to demonstrate the issue.
- Stop and report immediately if you encounter sensitive data.
- Do not publicly disclose the issue until we have confirmed it is resolved.
3. How to report
Email security@yanutek.com with:
- A clear description of the issue and its impact.
- Steps to reproduce, with proof-of-concept code or screenshots.
- Affected URL(s), parameters, and any payloads used.
- Your contact details (optional) for follow-up and credit.
4. Our commitments
- Acknowledge your report within 5 business days.
- Provide an initial triage assessment within 10 business days.
- Keep you informed as we investigate and remediate.
- Credit you publicly, with your permission, after the fix is deployed.
5. Safe harbour
We will not pursue or support legal action against researchers who report in good faith, comply with this policy, and avoid privacy violations, data destruction, and disruption of services. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make that fact known.
