SUMSLEGAL CENTER
SECURITY POLICY

Responsible Disclosure

A safe channel for reporting vulnerabilities without risking customer systems or data.

Version 2026-10-02Last updated 2 Oct 2026
Staging legal draft. The registered legal entity name and address of the SUMS operator must be inserted and reviewed by Indonesian counsel before commercial Production launch. The operational clauses below are designed around the current SUMS product and billing architecture.

1. Reporting a vulnerability

If you believe you found a security vulnerability in SUMS, email sumsstudio.id@gmail.com with the subject “Security Report”. Include a concise description, affected URL/component, reproduction steps and potential impact. Do not include unnecessary customer data or credentials.

2. Good-faith testing rules

Only test accounts, workspaces and data you are authorized to use. Do not access or modify another customer’s data, perform denial-of-service activity, send spam, exfiltrate secrets, persist access, deploy malware, or use social engineering. Stop testing if you encounter personal, confidential or third-party data.

3. What helps us respond

4. Coordinated disclosure

Please give SUMS a reasonable opportunity to investigate and remediate before publishing technical details. We will try to acknowledge valid reports promptly and keep reporters informed where practical.

5. No automatic bounty commitment

SUMS does not currently operate a guaranteed bug-bounty program. Any recognition or reward is discretionary unless a separate written program says otherwise.

6. Security architecture

SUMS uses layered controls such as server-side authorization, tenant isolation, database row-level security, privileged MFA, rate limiting, secret separation, verified payment webhooks, audit trails and backup/restore procedures. Public disclosure of these high-level controls does not authorize testing beyond this policy.