Legal & Compliance

Vulnerability Disclosure Policy

A safe, coordinated channel for good-faith security research.

Effective: 1 AUG, 2025 · Last revised: 31 July, 2026

This public policy is a baseline and does not create a contract, offer, or entitlement of any kind. A signed order form, enterprise agreement, or data-processing agreement may contain additional terms and prevails to the extent of a conflict. HEOSSI may amend this policy at any time; the version published at this URL at the time a report is submitted governs that report.

No bug bounty programme

HEOSSI does not currently operate a bug bounty programme and does not offer financial rewards, compensation, or consideration of any kind for vulnerability reports. No submission, regardless of severity or quality, creates an entitlement to payment. Any reward, if ever offered, requires a written agreement signed by HEOSSI before testing begins. The safe-harbour protections described below apply to qualifying good-faith research; they do not imply, and must not be construed as implying, any right to compensation.

Reporting

Report suspected vulnerabilities to security@heossi.com with the affected asset, reproduction steps, impact, evidence, and a safe contact method. Do not include personal data, credentials, secrets, or exploit code beyond what is strictly necessary to demonstrate the issue.

We aim to acknowledge qualifying reports within five (5) business days. Response and remediation timelines depend on severity and complexity and are determined solely by HEOSSI. Reports falling within the out-of-scope categories below may be closed without individual response.

Scope

HEOSSI welcomes good-faith research on its production solutions and the public-facing assets it directly operates.

In scope

  • HEOSSI solution portals and production services operated by HEOSSI, including bee.heossi.com and qnsi.heossi.com
  • The heossi.com corporate website and subdomains directly operated by HEOSSI
  • APIs and endpoints published by HEOSSI for public or authenticated use

Out of scope

The following are explicitly out of scope and do not constitute qualifying reports under this policy, regardless of the method or tool used to identify them:

  • DNS and email configuration observations, including SPF, DKIM, DMARC, MX, CAA, and DNSSEC records or policies, absent a demonstrated, reproducible compromise of mail flow or systems operated by HEOSSI;
  • TLS/SSL configuration or grade observations produced by third-party assessment tools (including, without limitation, SSL Labs, MXToolbox, and SecurityHeaders.io) absent a demonstrated exploit path;
  • Missing or misconfigured HTTP security headers absent demonstrated impact;
  • Findings produced solely by automated scanners without manual verification and a demonstrated exploit path;
  • Public information disclosure, including version strings, software banners, WHOIS records, directory listings of intentionally public content, and similar;
  • Self-XSS, clickjacking on pages without sensitive actions, and rate-limit observations without demonstrated bypass impact;
  • Social engineering, phishing, spam, or physical-security testing of any kind;
  • Third-party services, platforms, or infrastructure not operated by HEOSSI, including upstream providers, registrars, and hosting or CDN services. Findings in third-party services should be reported to the relevant operator.

HEOSSI may, at its sole discretion, review out-of-scope reports for informational value, but assumes no obligation to respond, remediate, credit, or reward.

Authorised good-faith research

Research is authorised under this policy only where all of the following conditions are met:

  • Test only systems you own or HEOSSI public assets clearly within the in-scope list above. Stop immediately if you encounter personal, customer, confidential, or classified data, and report the exposure without retaining, copying, or further accessing it.
  • Use the minimum interaction necessary to confirm the issue. Do not persist, pivot, escalate privileges, exfiltrate, alter, delete, or degrade data or services; do not phish, socially engineer, access physical premises, or affect other users.
  • Do not conduct denial-of-service or traffic-flooding attacks, deploy malware, perform credential attacks, run automated high-volume scanning, conduct supply-chain attacks, or test third-party services without that party's permission.
  • Keep the report and all related findings confidential until HEOSSI confirms remediation in writing or agrees in writing to disclosure.
  • Do not condition disclosure, non-disclosure, or continued confidentiality on payment or any other benefit. Demanding payment, threatening publication, or threatening to report "other vulnerabilities" contingent on reward disqualifies the report from this policy and voids safe-harbour protection.

Safe-harbour statement

Where research fully complies with this policy, is lawful in all applicable jurisdictions, avoids harm, and is reported promptly through the channel above, HEOSSI will not initiate civil action or refer the matter for prosecution solely on account of that research.

This statement: (a) cannot authorise conduct against third parties; (b) cannot waive any other person's rights; (c) does not bind law enforcement or regulators; (d) does not extend to accidental or intentional conduct outside this policy; and (e) is void where the research or the researcher's conduct breaches the confidentiality or no-payment-demand conditions above.

Excluded reports

Reports falling within the out-of-scope categories listed above, or limited to findings without demonstrated impact on systems or data operated by HEOSSI, will be closed without remediation obligation and without individual response. This includes, without limitation:

  • findings produced only by automated or online scanning tools;
  • reports of absent or non-strict configuration without a demonstrated exploit path;
  • duplicate reports of issues already known to HEOSSI or previously reported;
  • reports submitted after public disclosure of the finding by the reporter; and
  • reports accompanied by a demand for payment, a threat of disclosure, or any attempt to condition confidentiality on reward.

Closure of a report under this section is final and at HEOSSI's sole discretion.

Recognition

HEOSSI may, at its sole discretion and without obligation, acknowledge researchers who submit qualifying in-scope reports that lead to remediation. Recognition, where offered, does not constitute compensation and creates no precedent or entitlement.

Governing law

This policy and any dispute arising from or in connection with it are governed by the laws of the Republic of Singapore, and the courts of Singapore have exclusive jurisdiction.