Security Vulnerability Disclosure
We take security seriously. If you've discovered a vulnerability in our systems, please help us by reporting it responsibly.
How to Report
Please report security vulnerabilities to us via email:
info@mymoneyvision.com
Please include as much detail as possible, including:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any proof-of-concept code (if applicable)
- Your contact information for follow-up
Response Timeline
Initial Acknowledgment
Within 48 hours of receiving your report
Initial Assessment
Within 7 business days
Resolution Timeline
We aim to resolve critical issues within 30 days
In Scope
- Authentication and authorization vulnerabilities
- Data exposure or leakage
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- SQL injection or other injection attacks
- Server-side request forgery (SSRF)
- Business logic vulnerabilities
- Sensitive information disclosure
Out of Scope
- Social engineering attacks
- Physical attacks against our offices or data centers
- Denial of service (DoS/DDoS) attacks
- Spam or phishing attempts
- Issues in third-party services we use
- Vulnerabilities requiring physical access to a user's device
- Reports from automated vulnerability scanners without validation
Our Commitment
We are committed to working with security researchers to verify and address potential vulnerabilities. When you report a vulnerability in good faith:
- We will not pursue legal action against you
- We will work with you to understand and resolve the issue quickly
- We will acknowledge your contribution (with your permission) once the issue is resolved
- We will keep you informed of our progress
Note: Please do not publicly disclose any vulnerability until we have had reasonable time to address it. We appreciate your patience and responsible disclosure.
For general security questions or concerns, please contact us at info@mymoneyvision.com
