TINYFISH — VULNERABILITY DISCLOSURE & BUG BOUNTY POLICY ======================================================= How to report a security issue to TinyFish, and what to expect in return. Document ID IS.GRC_VulnerabilityDisclosureAndBugBountyPolicy_POL Version v1.1 Date 2026-09-15 Classification Public Owner TinyFish Security — CISO Deputy (andriy@tinyfish.io) Approver ISMS Steering Committee (ISMC) Contact security@tinyfish.io Machine-readable contact details: https://www.tinyfish.ai/.well-known/security.txt 1. PURPOSE ---------- TinyFish welcomes reports of security vulnerabilities in the systems and services we operate. This policy explains how to report a vulnerability to us, what is in and out of scope, the protections we extend to good-faith researchers, and how we recognise valuable reports. It follows the principles of ISO/IEC 29147 (vulnerability disclosure). 2. SCOPE -------- This policy applies to internet-facing systems operated by TinyFish under our primary domains (for example tinyfish.io and tinyfish.ai) and their subdomains. Third-party surfaces are out of scope. Some branded addresses point to systems run by our vendors (for example a billing page hosted by a payments provider). Vulnerabilities in those systems must be reported to the vendor; when a report reaches us, we may forward it to the vendor but cannot reward it under this policy. 3. HOW TO REPORT ---------------- Email security@tinyfish.io with: - A clear description of the issue and the affected URL, host, or endpoint. - Step-by-step reproduction instructions and a proof-of-concept (screenshots, a short video, or request/response captures). - Your assessment of the impact and, if you wish, a severity rating. - A contact address so we can follow up. Please report promptly, avoid accessing or modifying data that is not yours, and give us a reasonable opportunity to remediate before any public disclosure. 4. SAFE HARBOUR --------------- We will not pursue or support legal action against researchers who, in good faith: - Make a genuine effort to avoid privacy violations, data destruction, and service disruption; - Only interact with accounts they own or have explicit permission to access; - Report promptly and do not exploit the issue beyond what is necessary to demonstrate it; - Keep the finding confidential until we confirm it is resolved (see §8). Activity that is inconsistent with this policy — such as data exfiltration, denial-of-service, or social engineering of our staff or users — is not authorised and is not protected. 5. OUT OF SCOPE --------------- The following are generally not eligible for a reward, though we still appreciate the heads-up: - Email- and DNS-hardening recommendations — including missing or permissive DMARC, SPF, DKIM, CAA, MTA-STS, TLS-RPT or BIMI records — absent a demonstrated exploit. Reports that demonstrate an actual downgrade, interception or spoofing path are in scope and are assessed on impact. - Clickjacking on pages with no sensitive, state-changing action. - Missing security headers without a working attack chain. - Automated-scanner output submitted without manual verification or a proof-of-concept. - Findings on vendor-hosted or third-party surfaces (see §2). - Denial-of-service, volumetric, or resource-exhaustion issues. - Social engineering, phishing, or physical attacks. - Reports of software version disclosure or self-XSS with no realistic impact. 6. OUR COMMITMENTS ------------------ When you report in line with this policy, we aim to: Acknowledge your report Within 5 business days Provide an initial validity assessment Within 10 business days Keep you updated on remediation At meaningful milestones Confirm reward eligibility and amount Within 10 business days of validation Offer public credit (if you wish) On coordinated disclosure 7. REWARDS ---------- TinyFish does not operate a formal, obligation-bound bounty program. We review every report on its merits and, at our discretion, may pay a reward for findings that are valid, original, and impactful. Rewards are scaled to the assessed severity and real-world impact in our environment; low-impact or informational findings may receive a token award or none. Rewards are made under a confidentiality agreement covering the finding, its remediation status, and the amount. Duplicate, already-known, non-reproducible, and out-of-scope reports are not rewarded. 8. COORDINATED DISCLOSURE ------------------------- We ask that you keep the details of any finding confidential until we have remediated it and agreed a disclosure timeline with you — typically the earlier of a fix being deployed plus a short quiet period, or a mutually agreed date. We are happy to credit you in any write-up and to coordinate timing so that both sides can speak accurately about the issue. APPENDIX — TERMS & DEFINITIONS ------------------------------ Vulnerability A weakness in a system that could be exploited to compromise its confidentiality, integrity, or availability. Coordinated disclosure Publishing details of a vulnerability only after the affected party has had a reasonable opportunity to remediate. Safe harbour An assurance that good-faith security research conducted within this policy will not trigger legal action from TinyFish. In scope / out of scope Whether a target or finding type is eligible for review and reward under this policy. Reward A discretionary payment recognising a valid, impactful report; not a contractual entitlement.