Vulnerability Disclosure Policy
Peripamo Technologies Sdn Bhd ("Peripamo", "we", "us", "our") is committed to the security of our products, services and customers. We recognise the valuable role that independent security researchers play in improving that security. This policy describes how you can report vulnerabilities to us, what we ask of you, and what you can expect from us in return.
1. How to report a vulnerability
Please send reports to [email protected] with the subject line “Security Vulnerability Report”.
To help us triage and reproduce the issue, please include where possible:
- A clear description of the vulnerability and its potential impact;
- The affected product, service, domain, or endpoint;
- Step-by-step instructions, proof-of-concept code, or a video/screenshot demonstrating the issue;
- Any relevant logs, request/response pairs, or tooling used; and
- Your contact details and preferred attribution name, if you would like to be credited.
Reports in English are preferred. Please do not submit vulnerabilities through social media, public forums, or third-party channels.
2. What we ask of you
When investigating and reporting a vulnerability, we ask that you:
- Act in good faith and avoid actions that could degrade, disrupt, or damage our services or the data of our customers;
- Use only your own accounts and test data: never access, modify, or exfiltrate data that does not belong to you;
- Respect the privacy of our users, clients, and employees, and comply with all applicable laws, including the Computer Crimes Act 1997 of Malaysia;
- Avoid privacy violations, destruction of data, and interruption or degradation of our services (including denial-of-service testing and spamming);
- Do not use social engineering (phishing, vishing) against our employees, clients, or contractors;
- Do not demand payment or ransom in exchange for vulnerability details or for withholding a report; and
- Keep the vulnerability confidential until we have completed our remediation and agreed on a coordinated disclosure timeline with you.
3. Scope
This policy applies to the following properties and services operated by Peripamo:
- peripamo.com and all of its subdomains (including app.peripamo.com and trust.peripamo.com);
- Peripamo products and platform services provided to clients, where testing is permitted under your agreement with us; and
- Official Peripamo web assets and APIs.
Any service not explicitly listed above is considered out of scope. If you are unsure whether a target is in scope, contact us before testing.
4. Out of scope
The following issues are generally out of scope and may not receive a response or credit:
- Reports from automated scanners or tools without evidence of exploitable impact;
- Denial-of-service, resource-exhaustion, or load-testing attacks;
- Spam, phishing, or social engineering of our staff or customers;
- Missing security headers, cookie flags, or best-practice configuration findings without a demonstrable security impact;
- Self-XSS, logout CSRF, and login/unauthenticated CSRF without meaningful impact;
- Rate limiting, brute-force, or account lockout issues without demonstrated bypass;
- Version disclosure, directory listing, or information about publicly available documentation;
- Issues in third-party services or dependencies outside Peripamo's control (please report these to the respective vendor); and
- Physical attacks, social engineering, or attacks requiring access to an employee's or client's physical environment.
5. What to expect from us
Our commitment to reporters:
- Acknowledgement of your report within 3 business days of receipt;
- Triage and assessment of the issue, with an initial response on severity and validity typically within 10 business days;
- Regular updates on our remediation progress, and reasonable transparency about timelines;
- No legal action against researchers who comply with this policy and applicable law;
- Credit (at your discretion) when a fix is released, unless you prefer to remain anonymous; and
- A coordinated disclosure process: we aim to remediate critical issues within 90 days of a validated report, and we will discuss public disclosure timing with you.
6. Safe harbor
If you make a good-faith effort to comply with this policy during your research, Peripamo will consider your activity to be authorised and will not initiate or support legal action against you for accidental, good-faith violations of this policy. We will work with you to understand and quickly resolve any misunderstandings.
This safe harbor applies only to activity conducted in accordance with this policy and applicable law. It does not authorise activity that: (a) violates the privacy or confidentiality of our users or clients; (b) disrupts or degrades our services; (c) exfiltrates data beyond what is necessary to demonstrate the vulnerability; or (d) involves extortion or demands for compensation.
7. Recognition
While Peripamo does not currently operate a paid bug bounty programme, we value the contributions of the security community. For valid, high-quality reports we may, at our discretion, offer public acknowledgement on this page or a token of appreciation. All credit decisions are made at Peripamo's sole discretion.
Hall of thanks: to be populated as valid disclosures are resolved.
8. Exceptions and questions
If you need an exception to any part of this policy (for example, to test a client deployment, or if you are bound by a contractual security-testing agreement with Peripamo), please contact us first at [email protected]. Contractual penetration-testing engagements are governed by their own terms and are not restricted by this policy.
This policy is intended to be read and construed in accordance with the laws of Malaysia. Peripamo may update this policy from time to time; the date of the latest revision is shown at the top of this page.