Responsible disclosure
We take the security of attendee data and payments seriously. If you've found a vulnerability, here's how to tell us.
Scope
This policy covers excelenteawards.com and its subdomains — the ticketing flow, the attendee and admin dashboards, and our public APIs. Vulnerabilities in third-party services we use (Stripe, Resend, Cloudflare) should be reported directly to those vendors.
Safe harbor
We will not pursue legal action against researchers who make a good-faith effort to follow this policy, report a vulnerability promptly, and avoid privacy violations, data destruction, or service disruption while investigating.
Guidelines
- Do not disrupt or degrade service for other users.
- Do not access, modify, or exfiltrate data beyond what's needed to demonstrate the issue.
- Do not use social engineering against our staff, attendees, or sponsors.
- Report the issue as soon as you find it, before disclosing it publicly.
- Give us reasonable time to investigate and remediate before any public disclosure.
Out of scope
- Denial-of-service or volumetric attacks.
- Phishing or social engineering against staff or attendees.
- Attacks requiring physical access to a device or the venue.
- Vulnerabilities in third-party services we don't control.
- Spam, SEO, or content-injection reports with no security impact.
How to report
Use the form below. We aim to acknowledge every report within 3 business days and will keep you updated as we investigate.