Vulnerability Disclosure Policy
Last updated: August 2026 · v1.0 · For security researchers
In short
We welcome responsible disclosure of security vulnerabilities. If you find something, tell us privately and give us reasonable time to fix it before publishing. We will not pursue legal action against researchers who follow this policy in good faith.
1. How to report a vulnerability
Send your report to legal@bookify.mt. Please include:
- A clear description of the vulnerability
- Steps to reproduce it
- The affected URL, endpoint, or component
- Any proof-of-concept code or screenshots (keep them minimal — do not access or exfiltrate real user data)
- Your preferred method of contact for follow-up
We aim to acknowledge your report within 72 hours and provide an initial assessment within 10 working days.
2. Scope
This policy covers the following Bookify Malta services:
- bookify.mt — the marketing website
- app.bookify.mt — the Bookify dashboard and booking pages
- The Bookify Malta WP Integrator (WordPress plugin)
Third-party services (Google Cloud, Firebase, Epic Communications Ltd, DigitalOcean, SiteGround) are outside our scope. Please report vulnerabilities in those services through their own disclosure programmes.
3. Safe harbour
If you follow this policy in good faith, Bookify Malta will not pursue legal action or file a law-enforcement complaint against you for your research. To qualify for safe harbour:
- Report the vulnerability to us privately before disclosing it publicly.
- Give us a reasonable amount of time to investigate and fix the issue before publishing. We suggest 90 days from the date of our acknowledgement, or earlier if we confirm the fix is deployed.
- Do not access, modify, or delete data that does not belong to you. If a vulnerability gives you unintended access to data, stop and report it immediately.
- Do not degrade the service for other users (no denial-of-service testing, no automated scanning that overwhelms the platform).
- Do not use social engineering, phishing, or physical attacks against Bookify staff, customers, or infrastructure.
This safe-harbour statement is not a waiver of any rights Bookify may have, and it does not bind any third party. It reflects our commitment to working constructively with the security research community.
4. Prohibited testing
The following are not permitted under this policy:
- Denial-of-service or load-testing attacks
- Physical testing of facilities or equipment
- Social engineering of Bookify staff, customers, or partners
- Testing that accesses another user’s account or data without their explicit permission
- Testing that involves malware, ransomware, or destructive code
- Testing that violates Maltese or EU law
5. What to expect after you report
- Within 72 hours: We acknowledge receipt of your report.
- Within 10 working days: We provide an initial assessment, including whether we can reproduce the issue and our planned course of action.
- During remediation: We may ask for additional information. We will keep you informed of progress.
- After the fix: We will confirm when the fix is deployed. If you would like to be credited, we are happy to include your name (or handle) in our acknowledgements, with your permission.
6. Bounties
Bookify Malta does not currently offer a monetary bug bounty programme. We are grateful for responsible disclosures and are happy to publicly acknowledge researchers who help us improve the platform’s security.
7. Our commitment to you
We take every credible vulnerability report seriously. When a confirmed vulnerability is reported, we prioritise it based on severity and work to fix it as quickly as possible. Where the vulnerability affects our customers, we will communicate transparently about the nature of the issue, the steps we have taken, and any actions customers should take.