Responsible disclosure

We take the security of attendee data and payments seriously. If you've found a vulnerability, here's how to tell us.

Scope

This policy covers excelenteawards.com and its subdomains — the ticketing flow, the attendee and admin dashboards, and our public APIs. Vulnerabilities in third-party services we use (Stripe, Resend, Cloudflare) should be reported directly to those vendors.

Safe harbor

We will not pursue legal action against researchers who make a good-faith effort to follow this policy, report a vulnerability promptly, and avoid privacy violations, data destruction, or service disruption while investigating.

Guidelines

  • Do not disrupt or degrade service for other users.
  • Do not access, modify, or exfiltrate data beyond what's needed to demonstrate the issue.
  • Do not use social engineering against our staff, attendees, or sponsors.
  • Report the issue as soon as you find it, before disclosing it publicly.
  • Give us reasonable time to investigate and remediate before any public disclosure.

Out of scope

  • Denial-of-service or volumetric attacks.
  • Phishing or social engineering against staff or attendees.
  • Attacks requiring physical access to a device or the venue.
  • Vulnerabilities in third-party services we don't control.
  • Spam, SEO, or content-injection reports with no security impact.

How to report

Use the form below. We aim to acknowledge every report within 3 business days and will keep you updated as we investigate.