yebo®
Legal

Responsible Disclosure Policy

How to report a security vulnerability to Yebo, and our commitments to researchers.

Effective date: [to be set]Last updated: [to be set]

Yebo welcomes reports from security researchers acting in good faith to help keep our customers safe. This policy explains what is in scope, how to report, and what you can expect from us.

1. Scope

This policy covers the Yebo public website and production Services operated by [Yebo legal entity]. Testing must not degrade the Services, access data belonging to other customers, or violate applicable law.

2. How to report

Report suspected vulnerabilities to connect@yebonix.com, with steps to reproduce, affected URLs or components, and any supporting material. Please encrypt sensitive details using [PGP key / secure channel] where possible, and give us reasonable time to investigate and remediate before any public disclosure.

3. Our commitments

We will acknowledge your report within [3 business days], keep you informed as we investigate, work to remediate valid issues within a reasonable timeframe based on severity, and credit reporters who wish to be recognised once an issue is resolved.

4. Safe harbour

We will not pursue or support legal action against researchers who act in good faith, comply with this policy, remain within scope, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate the vulnerability.

5. Out of scope

The following are out of scope: denial-of-service attacks, social engineering of Yebo personnel or customers, physical attacks, spam, and testing against other tenants or third-party services integrated with the Services. Reports limited to missing best-practice headers without a demonstrable impact may be deprioritised.

Items shown in [square brackets] — legal entity, governing law, dates, service-level figures, and contact addresses — are to be finalised by Yebo and its counsel before publication.

Questions

Need more detail, or a compliance review with your team?

Talk to us about security, data protection, and contractual terms — including the full pack under NDA.

DISCUSS COMPLIANCE ↗