Security
Security & Responsible Disclosure Policy
If you discover a security vulnerability on the SmartResHomes website, please contact us immediately. We take all legitimate security reports seriously and will investigate and resolve verified issues as quickly as possible. Before submitting a report, please review the guidelines below outlining our responsible disclosure principles and bounty program requirements.
Section 1 – Core Principles
SmartResHomes will not pursue legal action against security researchers who report vulnerabilities responsibly and in accordance with this policy. We ask that you:
Allow Reasonable Time
Give us sufficient time to investigate and resolve the issue before publicly disclosing it.
Respect User Privacy
Do not access, modify, or retrieve personal information belonging to other users without their explicit permission.
Act in Good Faith
Avoid actions that could disrupt services, damage data, compromise privacy, or negatively affect other users.
Do Not Exploit the Vulnerability
Do not use the vulnerability to gain unauthorized access to sensitive information or systems.
Follow Applicable Laws
Ensure all testing and reporting activities comply with applicable local, state, and federal laws.
Section 2 – Bounty Program
SmartResHomes appreciates the efforts of ethical security researchers. At our sole discretion, we may offer monetary rewards for responsible disclosure of valid security vulnerabilities based on factors such as severity, impact, and exploitability.
To qualify for a bounty, you must:
- Follow all Core Principles outlined above.
- Report a genuine security or privacy vulnerability affecting our systems.
- Submit your report directly to our security contact.
- Immediately report any accidental access to sensitive information without attempting further exploration or exploitation.
Section 3 – Non-Eligible Submissions
The following types of reports are generally not eligible for bounty rewards:
- Spam, phishing, or social engineering reports unrelated to our infrastructure.
- Missing SPF, DKIM, or DMARC records.
- Clickjacking on non-sensitive pages.
- Rate-limiting or brute-force observations without demonstrable security impact.
- Denial-of-Service (DoS or DDoS) attacks.
- Vulnerabilities requiring rooted, jailbroken, or otherwise modified devices.
- Reports involving unsupported or outdated browsers, plugins, or operating systems.
How to Submit a Report
If you believe you have discovered a security vulnerability, please contact us with as much information as possible, including:
- Detailed reproduction steps.
- Description of the potential impact.
- Relevant screenshots, logs, proof-of-concept code, or other supporting evidence.
Contact Information
Report a Vulnerability
Reach out to our security contact using the details below.