BUILDSYNC LIMITED · Hong Kong
Vulnerability Disclosure Policy
Version: 2026-10-01-v1 · Effective date:
Contact address: Hong Kong Science and Technology Park
[email protected]
Reporting
If ordinary authorised use reveals a suspected vulnerability, stop at the minimum evidence necessary and report the affected service, approximate time, description and non-sensitive reproduction steps. Redact credentials, personal information and customer material. Ask for a secure transfer channel before sending sensitive evidence. A report does not require you to extract another person's data or prove a destructive impact.
Boundaries
This policy alone does not authorise penetration tests, automated scanning, load tests, social engineering, credential attacks, persistence, malware, accessing another tenant or testing third-party infrastructure. Obtain written scope and rules of engagement before active testing. Do not alter or delete data, interrupt service, retain customer material or disclose an exploitable issue publicly before a coordinated discussion. Nothing requires unlawful conduct or waives legally protected reporting.
Handling and protection
We will assess reports, coordinate remediation and communicate proportionately through the approved channel. Disclosure timing should reflect the risk and applicable reporting obligations. No bounty, response SLA, immunity or legal safe harbour is promised under this policy. Any additional researcher assurance requires written operator approval and cannot bind third parties. Do not publish internal topology, exploit details, provider credentials or customer identities in public acknowledgement. Requests for access, deletion or policy clarification belong with [email protected].
