Report a vulnerability
1. How to report
If you have discovered a vulnerability in the SeeU app, on the seeu.kz website or on our servers, please report it to security@seeu.kz. Describe the issue, the steps needed to reproduce it and its possible consequences, and attach supporting material such as screenshots, requests or video recordings. This contact address is also published in the standard security.txt file.
2. Scope of research
- the SeeU app for iOS and Android;
- the seeu.kz website and the subdomains that belong to us;
- the server interface used by the app.
We are particularly interested in vulnerabilities that make it possible to access another person’s account or messages, link an anonymous card to an account, track a person by means of the scanner signal, or circumvent mutual access or blocking.
3. Rules of research
- Use only your own test accounts. Do not access other people’s data beyond the minimum necessary to demonstrate the issue; should such access nevertheless occur, stop your research immediately.
- Do not disrupt the Service: denial-of-service attacks, mass messaging and load testing are not permitted.
- Do not use social engineering against users or staff, and do not carry out physical attacks.
- Do not disclose details of the vulnerability until it has been fixed or until 90 days have passed since your report, whichever occurs first, unless otherwise agreed with us.
4. Our commitments
We undertake:
- to acknowledge receipt of your report within 3 business days;
- to keep you informed of progress in fixing the vulnerability;
- not to pursue legal action for research conducted in good faith and in accordance with these rules;
- with your consent, to thank you publicly once the vulnerability has been fixed.
A paid bug bounty programme is not currently in operation.