Vulnerability Disclousre

  • Home
  • Vulnerability Disclousre

Vulnerability Disclosure

Last Updated: [Insert Date]

1. Introduction

At Hungry4Grub, we are committed to maintaining the security and integrity of our platform and user data.
This Vulnerability Disclosure Policy outlines how security researchers, users, and the public can responsibly report potential vulnerabilities or security concerns related to our website, web applications, APIs, or associated systems.

We value the contribution of security researchers who help us maintain a safe and secure environment for our customers and partners.


2. Scope

This policy applies to:

  • The Hungry4Grub website: https://hungry4grub.com

  • Any associated subdomains or applications operated under The Taskit Store

  • APIs, web services, and integrations used by Hungry4Grub

  • Admin dashboards, POS panels, and user login systems

Out of scope:

  • Third-party platforms, plugins, or integrations not developed or controlled by Hungry4Grub

  • Social media accounts or unrelated domains


3. Reporting a Vulnerability

If you believe you have discovered a security vulnerability in our systems, please report it responsibly by emailing us at:
📧 security@hungry4grub.com (or replace with your preferred contact email)

Please include the following details in your report:

  • A clear description of the vulnerability

  • Steps to reproduce the issue

  • Potential impact or affected components

  • Proof of concept (if available)

You will receive an acknowledgment within 5 business days of your report submission.


4. Responsible Disclosure Guidelines

To protect our users and systems, we ask that you:

  • Do not exploit the vulnerability beyond what is necessary to prove its existence.

  • Do not access, modify, or destroy any data belonging to others.

  • Do not publicly disclose the vulnerability until it has been resolved and coordinated with our security team.

  • Do not use automated scanners that generate high traffic or disrupt service.

We will not pursue legal action against individuals who identify and report vulnerabilities responsibly and in good faith, following this policy.


5. Our Commitment

When a valid security issue is reported:

  • We will acknowledge receipt of your report within 5 business days.

  • We will investigate and validate the vulnerability promptly.

  • We will provide updates on the status of the issue until resolution.

  • We will notify you once the vulnerability is fixed or mitigated.

  • With your consent, we may publicly credit you for the responsible disclosure.


6. Recognition

We currently do not offer monetary rewards or bug bounties, but we appreciate every valid report that helps us improve security.
Where appropriate, we will acknowledge contributors on our website’s Security Hall of Fame or equivalent recognition page.


7. Legal Safe Harbor

If you comply with this policy and act in good faith:

  • We will not initiate or support legal action against you for your security research.

  • Your activities will be considered authorized under this policy.
    However, this protection does not extend to:

  • Any actions that cause harm, disrupt services, or result in data exfiltration.

  • Violations of laws beyond what this policy can cover.


8. Continuous Improvement

Security is an ongoing process.
We continuously monitor, test, and update our systems to address potential vulnerabilities.
We encourage the community’s support in keeping Hungry4Grub safe for all users.


9. Contact Information

For all vulnerability-related submissions or security concerns:
📧 Email: security@hungry4grub.com
🌐 Website: https://hungry4grub.com


 

Cart (0 items)