YoWealth Responsible Disclosure Policy


Scope

This policy applies to all security researchers and enthusiasts who identify potential security vulnerabilities in YoWealth’s software applications. This includes, but is not limited to, web services, mobile applications, backend systems, and middleware services.


Our Commitment to Security

At YoWealth, we prioritize security and continuously work to protect our systems and users. Our development process includes strict quality assurance measures and security best practices. However, as with any complex system, vulnerabilities may arise.


Disclose

If you identify a potential security issue, we request that you report it to us confidentially. Please share details via __, following responsible disclosure practices. We appreciate and recognize security researchers who help us improve our platform.


How to Submit a Report

When reporting a security vulnerability, please provide as many relevant details as possible, including:

  • 1. A detailed explanation of how the vulnerability can be exploited and its potential impact.
  • 2. Step-by-step instructions on how the issue was discovered and how it can be reproduced.
  • 3. A proof of concept (PoC), screenshots, or other supporting evidence demonstrating the attack vector.
  • 4. Any known patches or suggested mitigations that could help address the issue.

Responsible Conduct

By submitting a vulnerability report, you agree to:

  • * Not exploit the vulnerability in any way beyond what is necessary for responsible disclosure.
  • * Keep all information confidential until YoWealth has resolved the issue.
  • * Not demand financial compensation for disclosing vulnerabilities unless a prior written agreement exists.

While YoWealth does not currently offer a bug bounty program, we value and appreciate security researchers' efforts. We are happy to acknowledge contributors with name recognition and a link to their profile (e.g., Twitter, website) in our Hall of Fame.


What Not to Do

When conducting security testing, you must avoid the following activities:

  • 1. Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attacks on YoWealth systems and products.
  • 2. Testing third-party systems that integrate with YoWealth products.
  • 3. Using YoWealth systems for malicious purposes against the company or its customers.
  • 4. Any testing that degrades service quality for YoWealth users.
  • 5. Uploading, sharing, or handling malicious software (e.g., viruses, malware) related to YoWealth.

YoWealth will not pursue legal action against security researchers who act in good faith and follow these guidelines. However, we reserve the right to recognize only those researchers who report legitimate and sufficiently severe issues.


Legal Considerations

This policy aligns with industry best practices for responsible vulnerability disclosure. However, it does not grant permission to engage in any activities that violate applicable laws or regulations. Additionally, researchers must ensure that their actions do not cause YoWealth to breach any legal obligations.


YoWealth Security Hall of Fame

Thank You!

We extend our sincere appreciation to our researchers who have responsibly disclosed vulnerabilities to YoWealth.


Your efforts help us maintain the security and integrity of our platform. 🚀🔒

We create custom solutions for you by utilizing the whole range of financial instruments, along with our in house views and your sustainability goals.

Like most similar websites, this website uses cookies. This page provides more information about cookies and how we use them. By using this website and agreeing to this policy, you consent to our use of cookies in accordance with the terms of this policy. learn more

Accept