1. Introduction
Keeping our systems and services secure matters to us. We recognise that security researchers can play an important role in identifying vulnerabilities before they can cause harm.
This policy explains how to report a potential security vulnerability to Yappl Limited, what we ask from anyone carrying out security research, and what you can expect from us in return.
We value the time and effort taken to report vulnerabilities responsibly. However, we do not operate a bug bounty programme and do not offer financial rewards for vulnerability reports.
Please read this policy before carrying out testing or reporting a vulnerability.
2. Scope
This policy applies to systems, websites, applications, services and infrastructure that are owned and operated by Yappl Limited.
This includes Yappl-owned digital services and domains where Yappl is responsible for the security of the underlying system.
Third-party systems, services or infrastructure that we use, link to or integrate with are not covered by this policy unless they are operated by Yappl.
If you're unsure whether something is in scope, please contact us at security@yappl.com before carrying out further testing.
3. Reporting a Vulnerability
If you believe you've identified a security vulnerability affecting a Yappl system or service, please email:
security@yappl.comPlease include as much useful information as you can, including:
- the affected website, application, IP address, service or system
- a clear description of the vulnerability
- the potential security impact
- the steps needed to reproduce the issue
- a benign, non-destructive proof of concept, where appropriate
- relevant screenshots, recordings or supporting files
- any suggested mitigation or remediation, if you have one
- your contact details, if you'd like us to keep you updated
Please avoid including unnecessary personal, confidential or sensitive data in your report.
The clearer the report, the easier it will be for us to investigate and respond.
4. What You Can Expect from Us
When you report a vulnerability in line with this policy, we'll:
- aim to acknowledge your report within five working days
- aim to complete an initial triage within ten working days
- assess the issue based on factors including its impact, severity and exploitability
- ask for more information if we need it to reproduce or understand the issue
- keep you updated where an issue requires further investigation or remediation
- let you know when we believe the vulnerability has been resolved, where appropriate
Some vulnerabilities will take longer to investigate or resolve than others. We may not be able to provide detailed information about our systems, customers or remediation activity.
If you would like an update, you're welcome to contact us. Where possible, please allow at least 14 days between requests so our teams can focus on investigating and resolving the issue.
5. Responsible Testing
We ask that any security research is carried out carefully, lawfully and in good faith.
You should only carry out the minimum testing necessary to establish that a vulnerability exists and understand its likely impact.
You must not:
- break any applicable law or regulation
- access, collect or download more data than is reasonably necessary to demonstrate the vulnerability
- access another person's account or data without their permission
- alter, delete, corrupt or otherwise interfere with data
- retain, share or redistribute personal, confidential or commercially sensitive information
- disrupt, degrade or interrupt any Yappl system or service
- carry out denial-of-service, distributed denial-of-service or other high-volume testing
- use destructive, excessively invasive or high-intensity automated scanning
- introduce malware, ransomware or other malicious software
- carry out social engineering, phishing or attempts to deceive Yappl employees, customers, suppliers or partners
- attempt physical attacks against Yappl premises, equipment or people
- use a vulnerability to establish persistent access to a system
- attempt to move laterally into other systems after identifying a vulnerability
- attempt to extract credentials, authentication tokens or cryptographic keys beyond what is necessary to demonstrate the issue
- test systems or services operated by third parties without their permission
- publicly disclose a vulnerability before coordinating disclosure with us
- demand payment or other compensation in return for reporting or withholding disclosure of a vulnerability
If you encounter personal, confidential or sensitive information while investigating an issue, stop accessing it as soon as you have enough information to demonstrate the vulnerability.
Please tell us what information was accessed and securely delete any copies as soon as they are no longer required.
6. Reports We May Not Treat as Vulnerabilities
We welcome reports that identify a genuine and demonstrable security risk.
We may close reports without further action where they relate only to theoretical risks, general security recommendations or issues without a meaningful security impact.
Examples may include:
- missing security headers without a demonstrated vulnerability
- TLS or cipher-suite configuration observations without a practical security impact
- software version disclosure without a demonstrated vulnerability
- clickjacking on pages with no sensitive actions
- issues that require unrealistic or highly improbable user interaction
- automated scanner output without evidence of an exploitable vulnerability
- previously reported or known issues
- reports relating entirely to third-party systems
- spam, phishing or other reports unrelated to a vulnerability in a Yappl-operated system
We will assess reports individually and may still investigate issues where the circumstances suggest a meaningful risk.
7. Coordinated Disclosure
Please give us a reasonable opportunity to investigate and resolve a vulnerability before making information about it public.
If you would like to publish details of a vulnerability you've reported, please contact us first so we can agree an appropriate disclosure approach and timing.
We'll aim to work constructively with you. We may ask for disclosure to be delayed where additional time is reasonably required to protect customers, users, systems or third parties.
Please do not disclose personal data, confidential information, security credentials or information that could unnecessarily place others at risk.
8. Good-Faith Security Research
We support responsible security research carried out in good faith.
Where you make a genuine effort to follow this policy, keep your testing proportionate and report vulnerabilities responsibly, Yappl does not intend to pursue legal action against you in relation to that research.
This does not give permission to act unlawfully, access third-party systems without authorisation or undertake activity that falls outside this policy.
It also cannot prevent a third party from taking action in relation to systems, services or data that they own or control.
If you're uncertain whether a particular activity is permitted under this policy, contact security@yappl.com before continuing.
9. Recognition & Rewards
Yappl does not currently operate a bug bounty programme and does not offer payment or other financial rewards for vulnerability reports.
We appreciate responsible reports and may, where appropriate, thank or acknowledge researchers who help us improve our security. We will not publish your name or details without your permission.
10. Privacy
We'll use the information you provide to investigate, manage and respond to your vulnerability report.
Where your report contains personal data, we'll handle that information in accordance with applicable data protection law and our privacy practices.
Please avoid collecting or submitting personal data unless it is necessary to explain the vulnerability.
11. Legal
This policy is intended to support responsible vulnerability disclosure and good-faith security research.
It does not give permission to carry out any activity that is unlawful or that could cause Yappl Limited, its customers, partners or suppliers to breach their legal or regulatory obligations.
Nothing in this policy creates a contractual obligation for Yappl to remediate a reported issue within a particular timeframe.
12. Policy Updates
We may update this policy from time to time as our systems, services or security processes change.
