How to report a security vulnerability and what to expect in return.
1. REPORTING. Report suspected vulnerabilities to security@bizmitra.example with steps to reproduce. Do not exploit, access other tenants' data, or run automated attacks.
2. SAFE HARBOUR. Good-faith research conducted under this policy will not lead to legal action, provided you avoid privacy violations, data destruction, and service disruption.
3. OUR COMMITMENT. We acknowledge reports within 3 business days, keep you updated on remediation, and credit reporters who wish to be named.
4. SCOPE. The Developer Platform, APIs, and connector. Out of scope: social engineering, physical attacks, and third-party services we do not control.
5. DO NOT. Publicly disclose before we confirm a fix, or demand payment as a condition of disclosure.