Vulnerability Disclosure Policy
BailaYa — operated by Infinity Curve LLC · Effective 2026-07-12
Infinity Curve LLC ("we") takes the security of BailaYa and our users seriously. We welcome reports from security researchers and members of the public, and we operate a coordinated vulnerability disclosure program. This policy explains how to report a vulnerability, what you can expect from us, and the rules for good-faith research.
How to report
Email your report to our security contact:
Please include, where possible:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it (proof-of-concept, requests, or screenshots).
- The affected URL, endpoint, or component.
- Any accounts or data involved, so we can reproduce and remediate.
Machine-readable contact details are also published at /.well-known/security.txt.
Our commitment
- We will acknowledge receipt of your report within 5 business days.
- We will investigate, keep you informed of our progress, and let you know when the issue is resolved.
- We will remediate confirmed vulnerabilities as quickly as is practical, prioritized by severity.
- We will credit you for your discovery if you wish (and if the report leads to a fix).
Scope
In scope:
- The BailaYa web application and API at www.bailaya.com.
Out of scope (please do not test these):
- Third-party services and platforms we integrate with (e.g. Zoom, Google, Microsoft, payment providers).
- Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks.
- Social engineering, phishing, or physical attacks against our staff, users, or facilities.
- Spam, or reports from automated scanners without a demonstrated, exploitable impact.
- Missing security headers or best-practice suggestions with no concrete security impact.
Safe harbor & guidelines for good-faith research
We will not pursue or support legal action against researchers who act in good faith and in accordance with this policy. To qualify, please:
- Only test against accounts you own or have explicit permission to use.
- Access only the minimum data necessary to demonstrate the issue, and never modify or destroy data.
- Respect user privacy — do not access, store, or share other users' personal data.
- Avoid actions that could degrade, disrupt, or damage our services or data.
- Give us a reasonable opportunity to remediate before disclosing the issue publicly.
- Comply with all applicable laws.
Coordinated disclosure
We ask that you keep the details of any vulnerability confidential until we have had a reasonable opportunity to remediate it — typically up to 90 days from our acknowledgement — and that you coordinate any public disclosure with us. We are happy to work with you on disclosure timing.
Recognition
We do not currently operate a paid bug-bounty program, but we are grateful for responsible disclosures and will publicly acknowledge researchers who report valid issues, with their permission.