Provzo

Website policy

Security disclosure

Reporting a vulnerability responsibly

Website policy · 4 sections

This is a website policy. It governs your use of this site. Bookings, payments and provider conduct are governed by the marketplace policies bundled in the Provzo app.

1. Reports are welcome

If you believe you have found a security problem in this website, the support chat, or the rules that protect conversations and bookings, please report it. A quiet report is more useful than a public one.

2. How to report

Open support chat and say that you are reporting a security issue. Include what you did, what you observed, and why you believe it is a problem. Keep the detail in the conversation rather than posting it publicly while it is being fixed.

A dedicated security address will be published here once monitored contact channels are set up.

3. Please stay within these lines

Do not access, modify or delete data belonging to anybody else. Do not run denial-of-service or high-volume automated testing against the site or its backend. Do not use social engineering against staff or providers, and do not attempt physical access.

Use only your own conversations and your own test accounts to demonstrate a finding. Stop as soon as you have confirmed a problem, and do not extract more data than is needed to show it.

4. What to expect

There is no bug-bounty programme and no payment is offered. Good faith reports that follow this policy will not be pursued, and genuine findings will be fixed.

Questions about this policy? Talk to support. The same text is available inside the app under Legal & business.