# Breeze - security contact and vulnerability disclosure # Template OU, Tornimae tn 7-79, 10145 Tallinn, Estonia # # Read the policy before you send anything: # https://www.breeze.pm/vulnerability-disclosure # # The short version, so nobody wastes their time: # # * There is NO bug bounty. We do not pay for reports. No bounty, no fee, no # swag, no "responsible disclosure reward". Unsolicited invoices are # disregarded and not replied to. # * Automated scanner output is IGNORED. If you have pasted a tool's report # without reproducing the issue yourself, do not send it. # * The following are OUT OF SCOPE without a working exploit demonstrated # against our production service: missing or "weak" HTTP security headers # (CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy); SPF, DKIM or # DMARC configuration and email spoofing; TLS version or cipher-suite # preferences; missing DNSSEC or CAA records; software version banners; # cookie flags on non-sensitive cookies; user or email enumeration; # self-XSS; clickjacking with no sensitive action; missing rate limiting; # and any "best practice" or compliance-checklist finding. # * We do not sign NDAs, contracts, invoices or vendor forms as a condition # of receiving a report, and we do not buy security audits from people who # email us unsolicited findings. # * Withholding details pending payment is extortion, not research. It ends # the conversation and will be reported to the relevant authorities. # # A clear report with a real reproduction is genuinely welcome, will be read by # a human, and will be credited publicly if you want the credit. Contact: mailto:security@breeze.pm Expires: 2027-08-18T00:00:00.000Z Preferred-Languages: en Canonical: https://www.breeze.pm/.well-known/security.txt Policy: https://www.breeze.pm/vulnerability-disclosure