Responsible Disclosure & Vulnerability Reporting Policy

1. Purpose

This Responsible Disclosure & Vulnerability Reporting Policy defines how Swazzy receives, assesses, and responds to reports of security vulnerabilities. It encourages responsible security research while protecting Swazzy, its customers, and partners from unnecessary risk.

2. Scope

This policy applies to:

  • Swazzy-owned and managed systems, applications, websites, and cloud services
  • Security researchers, customers, partners, and the general public

This policy does not authorise testing of customer-owned systems unless explicitly approved.

3. Guiding Principles

Swazzy is committed to:

  • Acting in good faith with security researchers
  • Investigating and validating reported vulnerabilities promptly
  • Remediating confirmed vulnerabilities in a risk-based manner
  • Communicating responsibly and transparently

4. How to Report a Vulnerability

Security vulnerabilities should be reported as soon as possible via:

Emailsecurity@swazzy.co
Subject: Responsible Disclosure – Vulnerability Report

Reports should include:

  • A clear description of the vulnerability
  • Affected system or service
  • Steps to reproduce (where possible)
  • Any supporting evidence (screenshots, logs, proof-of-concept)

5. Safe Harbour

Swazzy will not pursue legal action against individuals who:

  • Act in good faith
  • Avoid privacy violations, data destruction, or service disruption
  • Do not exploit vulnerabilities beyond proof-of-concept
  • Allow Swazzy reasonable time to remediate before public disclosure

This safe harbour does not apply to:

  • Denial-of-service attacks
  • Social engineering or phishing campaigns
  • Physical security testing
  • Testing involving customer data without authorisation

6. Swazzy Response Process

 

6.1 Acknowledgement

 
  • Vulnerability reports are acknowledged within 5 business days

6.2 Assessment

 
  • The vulnerability is validated and risk-rated
  • Impact and exploitability are assessed

6.3 Remediation

 
  • Remediation is prioritised based on risk
  • Temporary mitigations may be applied

6.4 Resolution & Communication

 
  • The reporter is notified once remediation is complete or mitigated
  • Disclosure timing is coordinated responsibly

7. Disclosure Guidelines

 

Swazzy requests that reporters:

  • Do not publicly disclose vulnerabilities without written consent
  • Allow a reasonable remediation window (typically up to 90 days for complex issues)
  • Coordinate disclosure where public acknowledgement is agreed

8. Recognition

 

At Swazzy’s discretion, security researchers may be acknowledged for responsible disclosure efforts. Swazzy does not currently operate a public bug bounty program.

9. Legal Considerations

 

This policy does not grant permission to:

  • Access or modify data not owned by the reporter
  • Perform activities prohibited by law
  • Circumvent safeguards beyond what is necessary to demonstrate the vulnerability

10. Review & Maintenance

 

This policy is reviewed annually or following significant changes to Swazzy systems or the threat landscape.

 
 
 
 
 
Scroll to Top