Back to home

Vulnerability Disclosure Policy

Last updated July 26, 2026

Introduction

Sunsay Ltd (the "Company", "we", "our" or "us") takes the security of our systems and the safety of our users seriously. We value the work of security researchers and the wider community in helping us keep our products and users safe. This Vulnerability Disclosure Policy explains how to report a security vulnerability to us, what you can expect from us in return, and the boundaries within which we ask you to conduct your research.

Scope

This policy applies to security vulnerabilities discovered in:

If you are unsure whether a system or issue is in scope, please contact us before testing and we will be glad to clarify.

How to report a vulnerability

Please send a report by email to security@sunsay.com. To help us triage and resolve the issue quickly, include as much of the following as you can:

Please submit one report per vulnerability and do not disclose the issue publicly until we have had a reasonable opportunity to investigate and remediate it.

Our commitment and response window

When you submit a report in good faith under this policy, we commit to:

We do not currently operate a paid bug-bounty program, and reports submitted under this policy are not eligible for monetary rewards.

Safe harbor

We consider security research and vulnerability disclosure activities conducted in good faith and in accordance with this policy to be authorized. We will not pursue or support legal action against you for accidental, good-faith violations of this policy, and we will work with you to understand and resolve the issue quickly.

If legal action is initiated by a third party against you for activities that were conducted in good faith and in compliance with this policy, we will make it known that your actions were authorized under this policy. Please note that the safe harbor described here applies only to claims under our control; it does not bind independent third parties.

Guidelines for good-faith research

To qualify for safe harbor, we ask that you:

Out of scope

The following issues are generally considered out of scope and are unlikely to be accepted under this policy:

Contact

For all security-related inquiries and vulnerability reports, please contact us at security@sunsay.com.