Report Security Issues

Report a Security Issue

If you have found a security vulnerability on babinio.com, we encourage you to let us know immediately. We review all legitimate vulnerability reports and do our best to resolve them quickly. Before reporting, please review the guidelines below, including our principles, reward guidelines, and what should not be reported.

Our Principles

If you follow the principles below when reporting a security issue to us, we will not pursue legal action or an enforcement investigation against you in response to your report. We ask that you:

  • Give us reasonable time to review and address an issue before making any information about it public or sharing it with others.
  • Do not interact with a private account (including modifying or accessing its data) without the account owner's consent.
  • Make a good faith effort to avoid privacy violations and service disruption, including data destruction or degradation of our services.
  • Do not exploit a security issue beyond what is necessary to demonstrate it.
  • Do not violate any other applicable laws or regulations.

Reward Program

We recognize and reward security researchers who help keep our users safe by reporting vulnerabilities. Rewards are given entirely at our discretion, based on risk, impact, and other factors. To potentially qualify for a reward, you must:

  • Follow our principles above.
  • Report a genuine security bug: identify a vulnerability in our services or infrastructure that creates a security or privacy risk. (We determine the severity of a reported issue at our discretion; not every bug is a security issue.)
  • Submit your report to us directly using the contact details below - please do not contact individual employees.
  • Disclose in your report if you inadvertently caused a privacy violation or disruption (such as accessing account data or confidential information) while investigating an issue.

We investigate and respond to all valid reports, though given the volume we receive, we prioritise by risk and it may take some time before you hear back. We reserve the right to publish reports.

Rewards

Rewards are based on the impact of the vulnerability reported. We may update this program over time based on feedback.

  • Please provide detailed, reproducible reports. Reports that are not detailed enough to reproduce the issue will not be eligible for a reward.
  • Where duplicate reports occur, we reward the first report we are able to fully reproduce.
  • Multiple vulnerabilities caused by the same underlying issue are treated as a single report for reward purposes.
  • Reward amounts are determined based on impact, ease of exploitation, and quality of the report.

Critical severity (up to £200): Vulnerabilities causing privilege escalation to admin level, remote code execution, or financial theft - e.g. remote code/shell execution, vertical authentication bypass, SQL injection that leaks sensitive data, or full account takeover.

High severity (up to £100): Vulnerabilities affecting the security of the platform or the processes it supports - e.g. lateral authentication bypass, disclosure of important internal information, stored XSS affecting other users, local file inclusion, or insecure handling of authentication cookies.

Medium severity (up to £50): Vulnerabilities affecting multiple users with little or no user interaction required to trigger - e.g. logic flaws in business processes, or insecure direct object references.

Low severity: Issues affecting individual users that require significant user interaction or prerequisites (e.g. a man-in-the-middle attack) to trigger - e.g. open redirects, reflected XSS, or low-sensitivity information leaks.

CONTACT US

WE'RE HERE TO HELP

Address: 147 Birchfield Road, Birmingham, United Kingdom, B19 1LH

Telephone: +44 7828 736030

Email: hello@babinio.com