Vulnerability Disclosure Policy
Introduction
Perkzup (“Perkzup”, “we”, “us”, or “our”) is committed to maintaining the confidentiality, integrity, and availability of its systems, infrastructure, and user data. While we continuously monitor, assess, and strengthen our security posture, vulnerabilities may nonetheless arise. We therefore encourage security researchers, customers, and members of the public to report potential security vulnerabilities responsibly and in good faith in accordance with this Policy. This Policy establishes the framework for coordinated vulnerability disclosure and sets out the standards applicable to responsible reporting.
Scope
This Policy applies to vulnerabilities affecting production systems directly owned and operated by Perkzup, including www.perkzup.com, official Perkzup subdomains, publicly available APIs, official Perkzup mobile applications, and backend infrastructure under our operational control. The Policy applies exclusively to live production environments and does not extend to staging, development, sandbox, or test environments unless expressly stated. Vulnerabilities arising solely from third-party platforms, regulated backend vendors, payment processors, card issuers, travel providers, or other independent service providers fall outside the scope of this Policy unless the vulnerability directly results from Perkzup’s own integration layer or system configuration.
Responsible Testing And Reporting
Before submitting a report, researchers should ensure that the identified issue affects a production system and that a reproducible proof of concept is available. Testing must be conducted in a manner that is proportionate, limited to what is necessary to demonstrate the vulnerability, and does not compromise system availability, user privacy, data integrity, or regulatory compliance obligations. Under no circumstances should testing involve accessing, modifying, downloading, or exfiltrating data that does not belong to the researcher, escalating privileges beyond what is strictly necessary to demonstrate impact, conducting denial-of-service attacks, disrupting services, or engaging in social engineering of Perkzup personnel or customers.
Vulnerability reports must be submitted to compliance@perkzup.com and should contain a clear description of the issue, detailed reproduction steps, affected URLs or endpoints, supporting technical evidence, and an explanation of potential impact. Reports should address a single vulnerability per submission to ensure clarity and efficient handling. Public disclosure of any vulnerability prior to remediation and written authorisation from Perkzup is strictly prohibited.
Safe Harbor
Where a researcher acts in good faith, complies fully with this Policy, limits testing to authorised scope, and promptly reports the vulnerability without exploiting it beyond proof of concept, Perkzup will regard such actions as authorised security testing conducted for the limited purpose of improving our security posture. In such circumstances, Perkzup will not initiate legal action against the researcher in connection with the reported activity. This Safe Harbor provision does not extend to conduct that violates applicable laws, including unauthorised access to computer systems, data exfiltration, fraud, extortion, coercion, or any activity exceeding the defined scope of this Policy.
Assessment And Remediation
Upon receipt of a valid vulnerability report, Perkzup will acknowledge the submission on a best-effort basis and conduct an internal assessment to determine severity, exploitability, and impact. We may request additional information where necessary and will provide an estimated remediation timeline where feasible. Reports will be handled confidentially and personal information provided by researchers will not be disclosed without consent unless required by law. Where appropriate and at our sole discretion, we may recognise contributors publicly or provide discretionary monetary rewards for significant vulnerabilities that were previously unknown to us. Participation in this program does not create any contractual right to compensation.
Severity Classification
Vulnerabilities are assessed internally based on their potential impact on confidentiality, integrity, availability, regulatory exposure, and financial risk. Critical vulnerabilities may include authentication bypass, remote code execution, unauthorised access to cryptocurrency wallets or private keys, arbitrary database execution, or exposure of significant volumes of sensitive personal data. High-severity issues may involve access to private customer information, account balance manipulation, unauthorised refunds, product delivery without payment, or privilege escalation within administrative systems. Medium-severity issues may include exploitable cross-site scripting or cross-site request forgery with limited impact, while low-severity issues typically involve minor configuration weaknesses or limited information disclosure without material risk. Final severity determination remains solely at Perkzup’s discretion.
Exclusions
This Policy does not apply to vulnerabilities originating exclusively from third-party services or infrastructure outside Perkzup’s operational control, automated scan reports lacking manual validation, denial-of-service attempts, social engineering attacks, theoretical vulnerabilities without demonstrable impact, email configuration observations (including SPF, DKIM, or DMARC records), SSL/TLS configuration preferences without security compromise, server banner disclosures, minor user interface issues, or vulnerabilities that have already been reported or publicly disclosed. Submissions lacking sufficient technical detail, vague allegations without reproducible evidence, or demands for payment prior to disclosure will not be considered valid.
Legal and Policy Modifications
Nothing in this Policy limits Perkzup’s rights or remedies under applicable laws. This Policy does not authorise any activity that would constitute unlawful access, interference, misuse of data, or breach of statutory obligations. Perkzup reserves the right to amend, suspend, or terminate this Policy at any time without prior notice. Participation in this disclosure program does not create any employment, partnership, agency, or contractual relationship.