Security and Vulnerability Disclosure
Last updated: August 30, 2026
We welcome good-faith security research that helps protect Sudomimus and its users. This policy explains how to report a potential vulnerability, which research practices we can support, and what you can expect after submitting a report.
1. Report a Vulnerability
Email security reports to [email protected]. Reports may be written in English or Simplified Chinese. Use a subject such as “Security report: <short summary>”.
Include enough detail for us to understand and reproduce the issue:
- the affected domain, endpoint, application, or component;
- the security impact and who could be affected;
- clear reproduction steps, prerequisites, and proof of concept;
- relevant timestamps, request identifiers, or sanitized evidence; and
- how we can contact you and whether you intend to disclose the issue publicly.
Include only the data necessary to demonstrate the issue. Redact credentials, tokens, personal data, and unrelated records whenever possible. If you unexpectedly access another person's data or an active secret, stop testing and report it immediately.
2. Scope
Security vulnerabilities in publicly accessible services operated by Sudomimus and in official Sudomimus software are in scope. A hostname, repository, or dependency is in scope only to the extent that Sudomimus controls it.
Issues that exist solely in a third-party service are outside our authority. Report those issues to the third party, although you may notify us when they also create a concrete risk to Sudomimus or its users.
3. Research Guidelines
To keep research safe and useful:
- use accounts and data you own or have explicit permission to use;
- make the minimum access needed to demonstrate the vulnerability, then stop;
- do not modify, delete, retain, or publicly expose data belonging to others;
- do not degrade availability or use denial-of-service, excessive traffic, spam, or destructive testing;
- do not use social engineering, phishing, malware, physical attacks, or attacks against Sudomimus personnel or users; and
- do not exploit a vulnerability beyond what is necessary to confirm and report it.
Automated tools are permitted only at a low, reasonable rate that does not disrupt the service or generate excessive traffic. If you are unsure whether a test is safe, contact us before proceeding.
4. Safe Harbor
When you make a good-faith effort to follow this policy, we will not initiate legal action against you solely for that research. We will work with you to understand the report and reduce risk to users.
This safe harbor does not authorize activity against third-party systems, excuse violations unrelated to security research, or bind independent third parties. If a third party initiates legal action and you complied with this policy, we may confirm that your research was conducted under this policy.
5. What to Expect
We aim to acknowledge a report within two business days and provide an initial assessment within five business days. Complex reports may take longer to investigate. We may ask for additional information and will share meaningful status updates when possible.
We assess reports according to demonstrated impact and exploitability. Duplicate, informational, or non-security reports may be closed without remediation, and response times may be longer during high-volume periods.
6. Coordinated Disclosure
Tell us about any planned public disclosure when you submit the report. Please give us a reasonable opportunity to investigate and remediate the issue before publishing technical details that could put users at risk.
We will work with you to agree on a disclosure timeline based on severity, active exploitation, remediation complexity, and user impact. We do not require indefinite silence, but we ask that you avoid public disclosure while it would create an immediate and unresolved risk.
7. Recognition and Rewards
Sudomimus does not currently operate a bug bounty or paid reward program. Submitting a report does not create an expectation of payment. We may acknowledge researchers who request recognition, subject to their consent and the report's outcome.
8. Product Support
The security channel is only for suspected vulnerabilities. For account, integration, or general product questions, use the Help Center.