Vulnerability Disclosure

Security Policy

bidyou.ai welcomes good-faith security research. This page describes how to report vulnerabilities responsibly and what you can expect from us in return.

Contact
security@crm-line.com · seguranca@crm-line.com (EN/PT)
PGP: not yet published — plain email accepted; treated as confidential.
RFC 9116: /.well-known/security.txt

Scope

The following assets are in scope for responsible disclosure:

Out of scope

What we commit to

What we ask of you

Safe harbour

If you conduct security research in good faith following this policy, we will:

This commitment extends to good-faith research that incidentally violates the letter of analogous EU/PT/UK statutes (CFAA-like, DMCA-like, Lei do Cibercrime PT n.º 109/2009), provided you act in accordance with this policy.

Bounties

We do not currently operate a paid bounty program. We may, at our discretion, offer rewards (acknowledgement, swag, or monetary) for impactful reports. The primary reward is recognition.

Coordinated disclosure

We are open to coordinated public disclosure of confirmed vulnerabilities once a fix has been deployed. Please coordinate timing via security@crm-line.com.

Policy version 1.0 · effective 2027-06-02 · reviewed annually
Operated by CRM-Line, Lda. (Portugal, NIF 507 830 466). Related: security.txt · Privacy · CRM-Line policy