Security
How to report a vulnerability in Bienvue.
If you believe you have found a security vulnerability in Bienvue — the dashboard, our websites, the API, guide links, public guide pages, or our television apps — please tell us at [email protected]. Write in English.
What to send
- What the vulnerability is, where it is, and what someone could do with it.
- The steps to reproduce it, with any proof-of-concept code, requests or screenshots.
- How to reach you, if you would like us to follow up or credit you.
We confirm receipt within three business days, keep you informed while we work on a fix, and tell you when it is fixed.
What we ask of you
- Test only against accounts, properties and screens you own, or have the owner’s permission to test.
- Don’t access, change, keep or share other people’s data. If you come across it, stop, and tell us what you saw.
- Don’t degrade the service for others: no denial-of-service testing, spam, or automated scanning that sends large volumes of requests.
- Don’t use social engineering, phishing or physical attacks against our staff, hosts, guests or properties.
- Give us a reasonable time to fix the problem before you disclose it publicly, and agree on the timing with us.
Safe harbor
If you make a good faith effort to follow this policy, we will consider your research authorized, will not bring legal action against you or ask a law enforcement agency to investigate you for it, and will not treat it as a breach of our Terms of Service. If someone else brings legal action against you for research that followed this policy, we will make it known that your work was authorized. This safe harbor covers only our own systems; it does not bind other companies, such as our hosting and payment providers, whose own policies apply to their systems.
Rewards
We don’t run a paid bug bounty. We are glad to thank you publicly, with your permission.
Our contact information is also published at /.well-known/security.txt.