This Policy invites security researchers (“Researchers”) to responsibly report security vulnerabilities discovered in Followme’s online assets.
1. Purpose
  • This Policy invites security researchers to responsibly report vulnerabilities in Followme systems.
2. Safe Harbor
  • Followme will not initiate legal action against Researchers who act in good faith, comply with this Policy, and do not exploit or disclose vulnerabilities beyond necessary proof-of-concept.
3. Scope
  • In-Scope: *.followme.com, api.followme.com, iOS & Android apps, public APIs, and cloud resources owned by Followme.
  • Out-of-Scope: Denial-of-service attacks, social engineering, physical attacks, and third-party services.
4. Rules of Engagement
  • Do not access, modify, or destroy data that does not belong to you.
  • Limit testing to your own accounts.
  • Avoid privacy violations or disruption to production systems.
  • Use test accounts where possible.
5. Submission Guidelines
  • Submit reports via email to [email protected] (PGP key available) and to include:
    • Vulnerability description and severity;
    • Step-by-step reproduction;
    • Impact assessment;
    • Suggest remediation;
    • Attach proof-of-concept code or screenshots.
6. Coordinated Disclosure Timeline
  • Followme will acknowledge reports within 24 hours, triage within 5 business days, and aim to fix issues within 90 days. Public disclosure is allowed after patching or after 90 days if mutually agreed.
7. Reward Tiers (USD)
  • HIGH: Critical vulnerabilities (e.g., remote code execution, authentication bypass) — $2,000 to $5,000.
  • MEDIUM: Significant issues (e.g., information leaks, privilege escalation) — $500 to $2,000.
  • LOW: Minor misconfigurations — swag or public recognition.
  • Rewards are determined at Followme’s sole discretion based on severity, impact, and report quality.
8. Hall of Fame
  • Researchers may opt for attribution in the public Hall-of-Fame and request CVE IDs where applicable.
9. Legal
  • All activities must comply with Malaysian and international law. Researchers must not violate export control or sanctions regulations.
10. Contact