Last updated July 26, 2026
Introduction
Sunsay Ltd (the "Company", "we", "our" or "us")
takes the security of our systems and the safety of our users seriously. We value the work
of security researchers and the wider community in helping us keep our products and users
safe. This Vulnerability Disclosure Policy explains how to report a security vulnerability
to us, what you can expect from us in return, and the boundaries within which we ask you to
conduct your research.
Scope
This policy applies to security vulnerabilities discovered in:
- The Sunsay marketing website and its subdomains (e.g. www.sunsay.com).
- The Sunsay mobile application (iOS and Android).
- The public APIs and backend services that support the above.
If you are unsure whether a system or issue is in scope, please contact us before testing
and we will be glad to clarify.
How to report a vulnerability
Please send a report by email to
security@sunsay.com. To help us triage and resolve
the issue quickly, include as much of the following as you can:
- A clear description of the vulnerability and its potential impact.
- The affected URL, endpoint, application screen, or component.
- Step-by-step instructions to reproduce the issue.
- Any proof-of-concept code, screenshots, or logs that demonstrate the issue.
- Your name or handle, if you would like to be credited.
Please submit one report per vulnerability and do not disclose the issue publicly until we
have had a reasonable opportunity to investigate and remediate it.
Our commitment and response window
When you submit a report in good faith under this policy, we commit to:
- Acknowledge receipt of your report within 5 business days.
- Provide an initial assessment and validation of the report within 10 business days.
-
Keep you informed of our progress as we work to remediate the issue, and let you know when
it has been resolved.
-
Credit you for your discovery if you wish, once the issue has been resolved (unless you
prefer to remain anonymous).
We do not currently operate a paid bug-bounty program, and reports submitted under this
policy are not eligible for monetary rewards.
Safe harbor
We consider security research and vulnerability disclosure activities conducted in good
faith and in accordance with this policy to be authorized. We will not pursue or support
legal action against you for accidental, good-faith violations of this policy, and we will
work with you to understand and resolve the issue quickly.
If legal action is initiated by a third party against you for activities that were conducted
in good faith and in compliance with this policy, we will make it known that your actions
were authorized under this policy. Please note that the safe harbor described here applies
only to claims under our control; it does not bind independent third parties.
Guidelines for good-faith research
To qualify for safe harbor, we ask that you:
-
Make a good-faith effort to avoid privacy violations, data loss, and service disruption.
-
Only interact with accounts you own or for which you have explicit permission from the
account holder.
-
Do not access, modify, delete, or exfiltrate data that does not belong to you; use the
minimum interaction necessary to demonstrate a vulnerability.
-
Give us a reasonable amount of time to resolve the issue before disclosing it publicly.
- Comply with all applicable laws.
Out of scope
The following issues are generally considered out of scope and are unlikely to be accepted
under this policy:
-
Denial-of-service (DoS/DDoS) attacks, volumetric testing, and any testing that degrades
service for other users.
- Social engineering, phishing, or physical attacks against our staff or offices.
- Reports from automated scanners without a demonstrated, exploitable impact.
-
Missing security headers, cookie flags, or other best-practice recommendations with no
demonstrated exploit.
- Missing SPF, DKIM, or DMARC records.
- Self-XSS that cannot be used to attack other users.
- Clickjacking on pages with no sensitive actions.
-
Vulnerabilities affecting only unsupported or end-of-life browsers, operating systems, or
application versions.
- Reports of outdated software versions without a demonstrated, exploitable impact.
Contact
For all security-related inquiries and vulnerability reports, please contact us at
security@sunsay.com.