Vialudi Vulnerability Disclosure Policy
Effective date: October 8, 2026 · Version: 1.0
Vialudi LLC ("Vialudi," "we") wants to hear from anyone who finds a security weakness in Vialudi before someone misuses it. This policy explains what you may test, how to test safely, how to report what you find, and what we promise in return.
If you follow this policy, we will treat your research as authorized and will not take legal action against you for it (Section 4).
1. What is in scope
- The Vialudi websites and web app that Vialudi LLC operates.
- The Vialudi iOS app, and the Vialudi Android app if and when it is available.
- The Vialudi application programming interfaces (APIs) those apps and websites call.
If you are unsure whether something is in scope, ask us first (Section 5) before you test it.
2. What is out of scope
Do not test the following. This policy gives you no permission to test them:
- Services we do not operate. For example, our payment processors, the Apple App Store and Google Play, our hosting, email, text-message and identity-verification providers, and the image service Unsplash. Report issues in those services to their owners under their own policies.
- Other people. This includes social engineering (phishing, pretexting or impersonating anyone) of Vialudi staff, contractors, partners or users.
- Physical attacks on any office, device or data center.
- Denial of service and any testing that degrades the Service for others: load or volumetric testing, resource exhaustion, and high-volume automated scanning.
- Spam and flooding: sending messages, invitations, reports, sign-ups or notifications to real users or in bulk.
We generally do not accept reports that show no security impact on their own, for example:
- missing best-practice headers or cookie flags;
- clickjacking on pages with no sensitive action;
- self-XSS;
- software version disclosure;
- issues that need an already-compromised device or account;
- findings that come only from automated scanner output.
You may still send them, and we will read them.
3. Rules of engagement
To stay within this policy, you must:
- Use only accounts you own or test accounts you create for research. Do not access, or try to access, any account or data that is not yours.
- Stop at the minimum proof. If you reach another person's data, stop immediately. Do not view, copy, change, download or keep more than you need to show that the issue exists. Report it to us right away.
- Do not exfiltrate, keep, share or publish other people's personal information, and delete anything you obtained once you have reported. We will never ask you to send us other people's private data. Describe what you could reach instead.
- Take extra care around minors. Do not create, contact, target or test against accounts of people under 18. Do not use research to message, locate or collect information about any minor. Stop and report immediately if you encounter a minor's information.
- Do not cause harm. That means:
- no denial of service;
- no destructive testing;
- no changes to other people's data, content or settings;
- no persistence, backdoors or malware;
- no pivoting to other systems.
- Do not use social engineering or physical access, and do not attack other users.
- Follow the law that applies to you, and this policy.
- Keep it confidential. Do not disclose the issue publicly or to anyone else until we have fixed it, or until the disclosure timeline in Section 7 allows.
- Researchers under 18: please have a parent or legal guardian submit or co-sign your report.
We may ask you to stop a test at any time. If you are unsure whether an action is allowed, stop and ask us first.
4. Safe harbor
If you make a good-faith effort to follow this policy, we will:
- consider your research authorized under the U.S. Computer Fraud and Abuse Act, the Michigan computer crime laws (MCL 752.791 et seq.) and similar laws, and not pursue or support legal action against you for it;
- consider your research authorized under the Digital Millennium Copyright Act's anti-circumvention rules (17 U.S.C. §1201) to the extent of your research, and not bring a claim against you under them;
- treat your research as consistent with our Terms of Service. Their acceptable-use restrictions do not apply to research you carry out under this policy, and we will not suspend or close your account for it;
- not refer your research to law enforcement. If a third party brings legal action against you over research you did under this policy, we will make it known that your research was authorized by us.
Safe harbor does not cover actions that break the rules in Section 3, and this policy cannot authorize testing of third-party services (Section 2). If you are unsure whether your testing would be covered, ask us before you start.
5. How to report
Report through one of these:
- The security report form in the Vialudi app and on our website. You will receive a reference number beginning with VR-. Keep it; we use it in every message about your report.
- Email security@vialudi.com.
Please include:
- what is affected, and where (a URL, screen or API route);
- the steps to reproduce the issue;
- what an attacker could achieve;
- any proof of concept;
- how we can contact you.
Keep any evidence to the minimum needed (Section 3). You may report anonymously, but then we cannot update you or credit you.
Please do not report security issues through general support channels, social media or public forums.
6. What we promise
- Acknowledgement within 3 business days, with your VR- reference if you did not already receive one.
- An initial assessment (whether we can reproduce it, and how severe we consider it) within 10 business days.
- Status updates at least every 30 days until the issue is resolved.
- Fixes, prioritized by severity (target timelines from confirmation):
| Severity | Target |
|---|---|
| Critical | 30 days |
| High | 60 days |
| Medium | 90 days |
| Low | 180 days |
Actively exploited issues are handled at once as security incidents.
- Duplicates and unclear reports: we will tell you if a report is a duplicate or we cannot reproduce it. We will not treat a good-faith report as a violation because it turned out to be low-severity or already known.
- We will tell you when the issue is fixed, and, where we can, how we verified it.
7. Coordinated disclosure
- Our commitment to you: we ask that you give us a reasonable time to fix an issue before you disclose it. We will work with you on the timing.
- Default: unless we agree otherwise, you may disclose 90 days after your report, or when the fix has shipped, whichever comes first.
- Severe issues: for severe issues we may ask for more time if a fix is still being deployed, and we will explain why. For an issue affecting users' personal information, we will first meet any legal duty to notify affected people.
- What any public write-up must exclude: personal information about any person, and any details that would help attack Vialudi users before they are protected.
8. Recognition and rewards
- No bounty: Vialudi does not currently offer a bug bounty or any payment for reports.
- Credit, if you want it: with your permission, we will thank you by name or handle on our security acknowledgements page once the issue is fixed.
- Changes: if we introduce rewards later, we will say so in a new version of this policy. Reports made before that version are not eligible unless it says otherwise.
9. Your information
- How we use it: we use the contact details and report you send only to handle your report, communicate with you and credit you if you ask. We handle them as described in our Privacy Policy.
- Who we share it with: we share them only as needed to fix the issue, or as the law requires.
10. Abuse of this policy
- Not research: extortion, threats, demands for payment in exchange for not disclosing, and testing that harms users or their privacy are not good-faith research. This policy does not protect them.
- How we handle it: we handle them through our security incident and trust and safety processes.
11. Changes and governing law
- Changes: we may update this policy. We will post the new version with its effective date. Research done under an earlier version is governed by the version in effect at the time.
- Governing law: Michigan law governs this policy, consistent with our Terms of Service (Section 17). Nothing in this policy limits any right you have under law.
12. Contact
Vialudi LLC
2222 W Grand River Ave, Ste A
Okemos, MI 48864, United States
security@vialudi.com