Reporting a Security Vulnerability
How to report a security vulnerability in GoSavis, and what happens after you do
How to report a vulnerability
If you believe you have found a security vulnerability in GoSavis, please write to security@gosavis.com with a description of the issue, the steps to reproduce it, and the pages or accounts involved.
If you would prefer to report through a co-ordinator, we will communicate with you through them.
This address is for security vulnerabilities. To report content or behaviour on GoSavis, please use the routes on our Safety page.
What happens after you report
We will acknowledge your report within 3 working days of receiving it. Within 5 working days of that acknowledgement we decide how serious the issue is, and tell you. If we cannot confirm the issue, we tell you that too, with our reasons.
While we investigate and fix it, we keep you informed at least every 30 days until your report is closed, and we tell you when the fix is live.
While you investigate
While investigating, please use only accounts you own or have permission to use, and access no more data than you need to show the issue. Please do not change or delete data, disrupt the service, or attempt social engineering, phishing or physical access. If you come across personal data, please stop, do not keep it, and tell us.
If your report includes personal data, such as a screenshot of an account, we keep it only for as long as the report needs it, and share it only with the people handling the report.
Payment and credit
GoSavis does not offer payment for reports. With your permission, we are glad to credit you by name once the issue is resolved.