This Policy invites security researchers (“Researchers”) to responsibly report security vulnerabilities discovered in Followme’s online assets.
1. Purpose
- This Policy invites security researchers to responsibly report vulnerabilities in Followme systems.
2. Safe Harbor
- Followme will not initiate legal action against Researchers who act in good faith, comply with this Policy, and do not exploit or disclose vulnerabilities beyond necessary proof-of-concept.
3. Scope
- In-Scope: *.followme.com, api.followme.com, iOS & Android apps, public APIs, and cloud resources owned by Followme.
- Out-of-Scope: Denial-of-service attacks, social engineering, physical attacks, and third-party services.
4. Rules of Engagement
- Do not access, modify, or destroy data that does not belong to you.
- Limit testing to your own accounts.
- Avoid privacy violations or disruption to production systems.
- Use test accounts where possible.
5. Submission Guidelines
- Submit reports via email to [email protected] (PGP key available) and to include:
- Vulnerability description and severity;
- Step-by-step reproduction;
- Impact assessment;
- Suggest remediation;
- Attach proof-of-concept code or screenshots.
6. Coordinated Disclosure Timeline
- Followme will acknowledge reports within 24 hours, triage within 5 business days, and aim to fix issues within 90 days. Public disclosure is allowed after patching or after 90 days if mutually agreed.
7. Reward Tiers (USD)
- HIGH: Critical vulnerabilities (e.g., remote code execution, authentication bypass) — $2,000 to $5,000.
- MEDIUM: Significant issues (e.g., information leaks, privilege escalation) — $500 to $2,000.
- LOW: Minor misconfigurations — swag or public recognition.
- Rewards are determined at Followme’s sole discretion based on severity, impact, and report quality.
8. Hall of Fame
- Researchers may opt for attribution in the public Hall-of-Fame and request CVE IDs where applicable.
9. Legal
- All activities must comply with Malaysian and international law. Researchers must not violate export control or sanctions regulations.
10. Contact
- For any enquiries, please contact [email protected]