Responsible Disclosure Policy
ENGLISH - EN
- ENGLISH - EN
Introduction
At Token.io, we take the security of our systems seriously. We value the work of security researchers who help us maintain the safety and privacy of our users and systems. This policy outlines how to report security vulnerabilities to us responsibly.
Scope
This applies to all Token.io public-facing assets.
How to Report
If you believe you have found a security vulnerability, please report it to us at: security@token.io
Please include the following in your report:
- A description of the vulnerability and its potential impact
- Detailed steps to reproduce the issue
- Any supporting evidence (screenshots, proof-of-concept code, HTTP requests/responses)
- Your contact details for follow-up questions
What We Ask of You
- Do not access, modify, or delete data that does not belong to you
- Do not perform actions that could negatively impact Token.io or its users (e.g., denial of service, social engineering, spam)
- Do not disclose the vulnerability publicly until we have had a reasonable opportunity to address it
- Act in good faith and comply with all applicable laws
- Only interact with accounts you own or have explicit permission to test
What You Can Expect from Us
- Acknowledgment of your report within 5 business days
- Regular updates on the status of your report
- Notification when the vulnerability has been remediated
Discretionary Bounty
Token.io may, at its sole discretion, offer a financial reward for the responsible disclosure of vulnerabilities that constitute a material threat to:
- The security or integrity of Token.io's platform and infrastructure
- The data, privacy, or security of Token.io's employees
- The data, privacy, or security of Token.io's customers
The decision to award a bounty, and the amount of any such award, is entirely at Token.io's discretion and is determined on a case-by-case basis. Not all valid findings will qualify for a bounty. The following factors may be considered:
- Severity and exploitability of the vulnerability
- Quality and clarity of the report
- Potential real-world impact to Token.io, its employees, or its customers
- Whether the vulnerability was previously known to Token.io
A bounty will not be awarded where:
- The finding does not represent a material threat to Token.io's platform, employees, or customers
- The researcher has not complied with this policy in full
- The researcher has engaged in coercion, threats, or extortion (see below)
- The vulnerability is out of scope as defined in this policy
Token.io's determination of whether a finding qualifies for a bounty is final and not subject to appeal.
Out of Scope
The following are considered out of scope and will not be accepted:
- Vulnerabilities in third-party applications or services
- Social engineering attacks (including phishing)
- Denial of service (DoS/DDoS) attacks
- Physical security issues
- Automated scanning output without a demonstrated exploit
- Reports of missing security headers without a demonstrated impact
- Reports related to SSL/TLS configuration best practices without a demonstrated exploit
- Clickjacking on pages with no sensitive actions
- Self-XSS (where the user can only attack themselves)
- Missing email best practices (SPF/DKIM/DMARC configuration)
- Software version disclosure without a demonstrated exploit
Safe Harbour
Token.io will not pursue legal action against security researchers who:
- Act in good faith and in accordance with this policy
- Avoid privacy violations — do not access, collect, or store personal data of Token.io users
- Avoid destruction or corruption of data
- Do not degrade or disrupt Token.io services
- Only exploit a vulnerability to the extent necessary to confirm its existence
- Report the vulnerability promptly and do not retain data obtained during research beyond what is necessary for the report
If legal action is initiated by a third party against you for activities conducted in accordance with this policy, Token.iowill take steps to make it known that your actions were conducted in compliance with this policy.
This safe harbour applies only to legal claims under Token.io's control and does not bind independent third parties.
Coercion, Threats, and Extortion
This policy exists to facilitate the responsible and good-faith reporting of security vulnerabilities. It does not provide protection for individuals who:
- Threaten to disclose vulnerabilities publicly or to third parties as leverage to obtain payment, recognition, or any other benefit
- Attempt to extort, coerce, or pressure Token.io or its employees into meeting demands
- Withhold vulnerability details contingent upon compensation or other conditions
- Engage in any conduct that constitutes blackmail or extortion under applicable law
Such conduct falls outside the scope of this policy and will be treated as a criminal matter. Token.io will report such behaviour to the relevant law enforcement authorities and will pursue all available legal remedies under applicable legislation, including but not limited to:
- United Kingdom: Computer Misuse Act 1990, Fraud Act 2006, and the Theft Act 1968 (Section 21 — Blackmail)
- European Union: Directive 2013/40/EU on attacks against information systems, and applicable national criminal codes of EU Member States
Token.io reserves the right to revoke safe harbour protections retroactively where a researcher's conduct is subsequently found to constitute coercion, extortion, or threats.
Changes to This Policy
Token.io reserves the right to modify this policy at any time. Researchers are encouraged to review this policy regularly.
Contact