Vulnerability Disclosure Policy

Last Updated: August 20, 2021

Vulnerability Disclosure Philosophy

Yat Labs believes effective disclosure of security vulnerabilities requires mutual trust, respect, transparency and common good between Yat Labs and Security Researchers. Together, our vigilant expertise promotes the continued security and privacy of Yat Labs creators, products, and services.

Security Researchers

Yat Labs accepts vulnerability reports from all sources such as independent security researchers, industry partners, vendors, customers and consultants. Yat Labs defines a security vulnerability as an unintended weakness or exposure that could be used to compromise the integrity, availability or confidentiality of our products and services.

Scope

This policy applies to any digital assets owned, operated, or maintained by Yat Labs, including public facing websites.

Our Commitment to Researchers

What We Ask of Researchers

Vulnerability Reporting

Yat Labs recommends that security researchers share the details of any suspected vulnerabilities across any asset owned, controlled, or operated by Yat Labs (or that would reasonably impact the security of Yat Labs and our users) using the web form below. The Yat Labs Security team will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and then take appropriate action for resolution.

If you have any recommendations, please contact us at disclosure@y.at.