Security
Reporting a security issue
If you have found a security problem in Loggio, we want to hear about it.
How to reach us
Email security@logg.io. Include enough detail for us to reproduce the issue:
what you did, what you saw, and where. If you are not sure whether something counts, send it
anyway.
What we commit to
- A person reads it and replies within 3 business days.
- We tell you our assessment, and whether we are fixing it, within 10 business days.
- We tell you when it is fixed.
- We will credit you by name if you want the credit, and stay quiet about you if you do not.
Safe harbor
If you follow this policy, we will treat your research as authorized, we will not pursue legal
action against you, and we will not report you to law enforcement. If someone else brings a
claim against you for research that followed this policy, we will say publicly that it was
authorized.
Following this policy means:
- Stop as soon as you have confirmed the issue. Do not keep going to see how far you can get.
- Do not access, copy, modify, or keep data that is not yours. If you come across someone
else's data by accident, stop and tell us what happened.
- Do not use social engineering, phishing, or physical access against Loggio staff, customers,
or suppliers.
- Give us a reasonable chance to fix the issue before you talk about it publicly. Ninety days
is our default, and we are happy to agree on something different with you.
In scope
Anything Loggio runs or ships: our websites, our customer portal and its API, our mobile
application, and the hardware we supply with it.
Out of scope
- Systems belonging to our suppliers or customers. If the issue is in someone else's product,
please report it to them.
- Findings from automated scanners with no demonstrated impact.
- Missing hardening headers, or best-practice suggestions with no exploitable consequence.
What this is not
We do not run a paid bug bounty. There is no reward beyond credit and our genuine thanks.