Trust
Responsible Disclosure
Reporting
Please send reports to ty@syladon.com. Include enough detail to reproduce the issue: the affected URL or endpoint, a description of the behavior, and any relevant request or response information. Please do not include third-party data.
Scope
This policy covers the public website at syladon.com and its contact endpoint. Subdomains, third-party services, client systems, employee accounts, and any other systems are out of scope unless Syladon Technologies gives written authorization.
Good-faith expectations
We ask that researchers:
- Make a good-faith effort to avoid privacy violations and disruption.
- Only interact with accounts they own or have explicit permission to test.
- Give us a reasonable opportunity to investigate and remediate before any public disclosure.
Please do not
- Access, modify, or retain data belonging to other people.
- Perform denial-of-service or load/stress testing.
- Use social engineering, phishing, or physical attacks against anyone.
- Run automated scanning that degrades the service for others.
- Perform destructive testing or attempt to pivot to other systems.
- Publicly disclose an issue before we have coordinated on it.
What to expect from us
We aim to acknowledge good-faith reports within three business days and provide reasonable status updates while we investigate. This is not a paid bug-bounty program, and no monetary reward is implied.
Safe harbor
If you make a good-faith effort to comply with this policy, Syladon Technologies will consider your research authorized and will not initiate or recommend legal action against you for that research. If a third party initiates legal action, we may state that your activity was conducted in accordance with this policy. This commitment does not authorize activity involving third-party systems or excuse violations of law unrelated to the research. Read this policy alongside our Terms of Use.