If you have found a security vulnerability in Super Save Protocol, we want to hear about it. This policy explains how to report it, what is in scope, and the commitments we make to researchers who act in good faith.
01 How to report
Email security@supersaveprotocol.com with:
- a description of the issue and its potential impact;
- clear steps to reproduce, including any proof-of-concept;
- the URLs, parameters or endpoints affected;
- your contact details, and whether you would like to be credited.
Please report in English, and please do not disclose publicly until we have had a chance to fix it.
02 Our commitments
- We acknowledge your report within 3 business days.
- We give an initial assessment, including severity, within 10 business days.
- We keep you updated at least every 14 days until the issue is resolved.
- We aim to remediate critical issues within 7 days, high within 30, medium within 90.
- We credit you publicly if you would like, once the fix is deployed.
- We will not pursue legal action against researchers who follow this policy in good faith, and we will make that position clear if a third party raises a complaint.
03 In scope
- This website and its subdomains.
- The SSP registry application.
- Our public API endpoints.
04 Out of scope
- Denial of service, volumetric or stress testing of any kind.
- Social engineering of our staff, Members or suppliers, and physical attacks.
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing best-practice headers or cookie flags with no demonstrated exploit.
- Vulnerabilities in third-party services we do not control.
- Self-inflicted issues requiring a compromised device, or issues requiring an outdated browser.
- Reports of theoretical weaknesses in published cryptographic standards.
05 Rules of engagement
To stay within this policy you must:
- use only your own test accounts, or accounts you have explicit permission to test;
- stop as soon as you confirm a vulnerability — do not enumerate, exfiltrate or retain data;
- never access, modify or delete another Member's or user's data;
- never degrade the availability or integrity of the service;
- keep what you find confidential until we confirm the fix, or 90 days have passed and we have not responded;
- comply with applicable law throughout.
If you inadvertently access data that is not yours, stop, delete it, and tell us in your report.
06 Rewards
We do not currently operate a paid bug bounty. We offer public acknowledgement, a written reference where useful, and our genuine thanks. If that changes we will update this page.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.