Responsible Disclosure
A safe channel for reporting vulnerabilities without risking customer systems or data.
1. Reporting a vulnerability
If you believe you found a security vulnerability in SUMS, email sumsstudio.id@gmail.com with the subject “Security Report”. Include a concise description, affected URL/component, reproduction steps and potential impact. Do not include unnecessary customer data or credentials.
2. Good-faith testing rules
Only test accounts, workspaces and data you are authorized to use. Do not access or modify another customer’s data, perform denial-of-service activity, send spam, exfiltrate secrets, persist access, deploy malware, or use social engineering. Stop testing if you encounter personal, confidential or third-party data.
3. What helps us respond
- clear reproduction steps;
- request/response details with secrets removed;
- browser/platform information where relevant;
- a suggested remediation if you have one; and
- a safe way to contact you for follow-up.
4. Coordinated disclosure
Please give SUMS a reasonable opportunity to investigate and remediate before publishing technical details. We will try to acknowledge valid reports promptly and keep reporters informed where practical.
5. No automatic bounty commitment
SUMS does not currently operate a guaranteed bug-bounty program. Any recognition or reward is discretionary unless a separate written program says otherwise.
6. Security architecture
SUMS uses layered controls such as server-side authorization, tenant isolation, database row-level security, privileged MFA, rate limiting, secret separation, verified payment webhooks, audit trails and backup/restore procedures. Public disclosure of these high-level controls does not authorize testing beyond this policy.