Security

How to report a vulnerability in Bienvue.

If you believe you have found a security vulnerability in Bienvue — the dashboard, our websites, the API, guide links, public guide pages, or our television apps — please tell us at [email protected]. Write in English.

What to send

We confirm receipt within three business days, keep you informed while we work on a fix, and tell you when it is fixed.

What we ask of you

Safe harbor

If you make a good faith effort to follow this policy, we will consider your research authorized, will not bring legal action against you or ask a law enforcement agency to investigate you for it, and will not treat it as a breach of our Terms of Service. If someone else brings legal action against you for research that followed this policy, we will make it known that your work was authorized. This safe harbor covers only our own systems; it does not bind other companies, such as our hosting and payment providers, whose own policies apply to their systems.

Rewards

We don’t run a paid bug bounty. We are glad to thank you publicly, with your permission.

Our contact information is also published at /.well-known/security.txt.