Security Reports
Responsible Disclosure Policy
This Policy explains how security researchers and users may report vulnerabilities to Emailble responsibly.
1. Purpose
PriceCal Pte Ltd welcomes responsible reports of security vulnerabilities affecting Emailble. This Policy is intended to allow good-faith reporting while protecting customers, recipients, data, systems and service availability.
2. Permitted Good-Faith Research
Good-faith testing should be limited to the researcher’s own account, own workspace, own data and non-destructive techniques. Researchers must stop immediately if they encounter personal data, customer data, confidential information, credentials, payment data or any data that does not belong to them.
3. Prohibited Research Conduct
- Accessing, copying, modifying, deleting, exporting or disclosing data that does not belong to the researcher.
- Disrupting, degrading, overloading, scanning aggressively or denying service to Emailble or providers.
- Running phishing, spam, malware, credential attacks, social engineering or physical attacks.
- Testing third-party providers, connected customer accounts or infrastructure outside the authorised Emailble surface.
- Publicly disclosing a vulnerability before Emailble has had reasonable time to investigate and remediate.
- Using a vulnerability for extortion, commercial pressure, data access, persistence, privilege escalation beyond proof, or unauthorised benefit.
4. Report Contents
- A clear description of the suspected vulnerability.
- Steps to reproduce using the researcher’s own account or test data.
- Affected URL, feature, endpoint, request or configuration where applicable.
- Screenshots or proof-of-concept details that do not expose other people’s data.
- Potential impact and suggested remediation if known.
- Researcher contact details for follow-up.
5. Emailble Response
Emailble may acknowledge, investigate, request more information, validate, prioritise and remediate reports according to severity, exploitability, affected data, customer risk and operational capacity.
Emailble does not currently offer a public bug bounty or guaranteed reward unless expressly stated in a separate written program. Recognition, if any, is discretionary and subject to lawful, responsible conduct.
6. Safe Harbour Limits
PriceCal Pte Ltd does not intend to pursue legal action for good-faith research that follows this Policy and does not harm users, data, systems, providers or service availability. This safe-harbour statement does not protect unlawful conduct, extortion, data theft, privacy violations, provider attacks, malware, phishing, public disclosure before remediation or activity outside the scope of this Policy.
7. How to Report
Security reports should be submitted through the contact panel on this page. Do not include sensitive data, passwords, full tokens, private keys, customer contact lists or unnecessary personal data in the initial report.
Security Reports
To reduce public email harvesting, the address is hidden until requested.