PocketBay Security Vulnerability Disclosure and Shared Responsibility Policy PocketBay Technologies Limited | pocketbay.com Last Updated / 最后更新: 2026-07-08 Effective Date / 生效日期: 2026-07-08 Public URL / 建议公开地址: /legal/security Contact / 联系方式: support@pocketbay.com
Implementation Note
This document is for the security page, vulnerability reports, enterprise questionnaires, account compromise/secret leak handling and developer security responsibilities.
Shared Responsibility Model
PocketBay is responsible, within reasonable scope, for maintaining platform infrastructure, dashboards, APIs, core services, internal security processes, access controls, monitoring, vulnerability remediation, backup/disaster recovery capabilities where applicable, and upstream-provider management. PocketBay's security responsibilities do not mean PocketBay is responsible for your code, dependencies, configurations, secrets, permissions, databases, business logic, end users, third-party integrations or compliance requirements.
You are responsible for account security, team permissions, code security, dependency security, open-source licensing, secret management, environment variables, database access, application authentication and authorization, input validation, log redaction, backups, monitoring, alerts, compliance, end-user notices and security incident response for your apps.
Shared-responsibility boundaries vary by plan, feature, third-party integration, enterprise agreement, deployment method, region and configuration. Unless PocketBay expressly commits in writing, any security feature, monitoring, DDoS mitigation, certificate, auto-remediation or AI diagnostic does not constitute an absolute security or compliance guarantee.
Vulnerability Disclosure Scope and Rules
If you in good faith discover a security vulnerability in the PocketBay platform, dashboard, APIs, documentation, public domains or PocketBay-owned systems, send a report to support@pocketbay.com with the subject "Security Vulnerability Report." Include a description, impact, reproduction steps, evidence, URLs, account information where applicable, risk assessment and contact information.
You must not access, modify, delete, export or damage others' data without authorization; persist control; move laterally; use social engineering, phishing, spam, DDoS, brute force, physical attacks, employee harassment, extortion; publicly disclose unremediated vulnerabilities; or exploit vulnerabilities beyond the minimum necessary.
PocketBay currently does not promise bug bounties or monetary rewards. For research conducted in good faith, safely, with minimized impact, timely reporting and compliance with this policy, PocketBay generally will not pursue legal action for the research itself; however, this safe harbor does not apply to unlawful, malicious, destructive, privacy-invasive, extortionate, publicly exploitative or third-party-rule-violating activity.
Security Incidents and User Obligations
If you discover account compromise, secret leakage, exposed databases, malicious code, abnormal traffic, unauthorized access, data breach, vulnerability, phishing page, malicious dependency, open-source license risk or end-user security incident, you must promptly remediate and notify PocketBay. You must cooperate with PocketBay, upstream providers, payment institutions, regulators and affected parties in investigations and remediation.
During security incidents, PocketBay may restrict, suspend, isolate, restart, roll back, delete, disable network, disable APIs, revoke secrets, reclaim resources, block domains, preserve logs or take other protective measures. PocketBay is not liable for refunds, damages or compensation for good-faith security measures unless required by law.
You must not publicly disclose details that may affect the security of PocketBay, other users or third parties unless PocketBay has confirmed remediation or law requires disclosure. You should avoid leaking secrets, personal information or sensitive data in logs, environment variables, public repositories, error pages, screenshots, Discover listings or support requests.