Legal
Responsible disclosure
How to report a vulnerability or a data concern to Birdtold, what we commit to in return, and the safe harbour that applies to good-faith research.
Draft — pending legal review. Not yet in force.
Where to send a report
Send security reports to security@birdtold.me. This is a role address monitored by the desk; it is not an individual. The same route is published at /.well-known/security.txt.
If the report contains anything you would not send in the clear, encrypt it to the key below. If you cannot encrypt, write to security@birdtold.me without the detail and we will arrange a channel before you send it. Do not post the detail publicly first.
What to include
A description of the issue, the host or URL affected, the steps needed to reproduce it, and what an attacker could obtain or do. A single clear proof of concept is worth more than a scanner export. Tell us if you believe the issue is already being exploited.
Include an address we can reply to. Reports may be anonymous; we will still act on them, but we cannot tell you what happened next.
Our timeline
We acknowledge a report within [NUMBER] working days of receipt. Acknowledgement means a human at the desk has read it, not that it has been triaged.
We give an initial assessment — whether we consider it a vulnerability, and its severity — within [NUMBER] working days of acknowledgement, and we keep you informed at intervals until it is closed. When a fix ships, we tell you. If we decide not to act, we tell you that too, and why.
What we ask of you
Work only against your own accounts and your own data. Do not access, modify, exfiltrate or retain data belonging to anyone else; if you encounter such data incidentally, stop, tell us, and delete what you hold. Do not degrade the service: no denial of service, no volumetric or brute-force testing, no spam.
Do not use social engineering, phishing or physical intrusion against our people, suppliers or premises. Do not test the third-party booking widget or any other supplier's infrastructure under this policy — report those to the supplier concerned.
Give us a reasonable period to remediate before disclosing publicly, and coordinate the timing with us. We will not ask you to stay quiet indefinitely.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will not initiate or support legal action against you in relation to it, and we will not report you to law enforcement for it. Should a third party bring action against you for activity conducted in compliance with this policy, we will make that compliance known.
This safe harbour covers our own systems only. It cannot waive the rights of any third party, and it does not apply to conduct outside the scope above. If you are unsure whether something is in scope, ask first at security@birdtold.me.
Out of scope
Missing best-practice headers with no demonstrated impact, reports produced solely by an automated scanner, rate-limiting on unauthenticated public pages, issues in third-party services we do not operate, and self-inflicted findings requiring a compromised device or a browser extension.
Rewards
We run no paid bug-bounty programme. With your permission we credit reporters here once the issue is closed. You may ask to remain anonymous.
PGP key
Encrypt sensitive reports to the key below. Verify the fingerprint out of band before you rely on it.
[PGP KEY BLOCK]
Anything that is not a security issue
Correspondence about a finding, a named party or a correction goes to once@birdtold.me and is handled under the right of reply, not under this policy.