Tarseek Legal Center
Vulnerability Disclosure Policy
Tarseek welcomes good-faith reports of security vulnerabilities. This policy describes how to report them. There is no bug bounty unless Tarseek later publishes one.
1. Security contact
Email hello@tarseek.com.
2. Scope
In-scope: Tarseek production websites, APIs, and authentication systems that Tarseek operates. Out of scope unless expressly listed: Model Provider infrastructure, third-party apps, and denial-of-service testing.
3. Safe / good-faith testing
Test only to the extent needed to demonstrate a vulnerability. Use your own accounts. Stop if you encounter data that is not yours.
4. Prohibited testing
- destructive testing or data deletion;
- denial-of-service or volumetric attacks;
- social engineering of Tarseek staff, customers, or providers;
- physical attacks;
- accessing, copying, or exfiltrating data beyond the minimum needed to prove the issue;
- ransomware or malware deployment.
5. Report format
Include: summary, affected URL or endpoint, steps to reproduce, impact, and any proof-of-concept limited to demonstration. Do not include unnecessary customer data.
6. Disclosure process and expectations
Tarseek will acknowledge reports, investigate, and remediate based on severity. Coordinated disclosure is preferred. Do not publicly disclose an unfixed issue without a reasonable opportunity to patch, except as required by law.
Tarseek will not pursue legal action against researchers who comply with this policy in good faith. This is not a license to violate law or third-party terms.
Version history
This is the current published version. Prior versions will be retained at stable URLs rather than silently overwritten.
Contact
Questions about this document: hello@tarseek.com. General inquiries: hello@tarseek.com.
