# Bitcoin4U (Innovative Horizon Technologies Inc.) - vulnerability disclosure # # We appreciate security researchers who disclose responsibly and help keep # our customers' money and personal information safe. Report to the Contact # address below; the full policy, including scope and safe harbour, is at # https://bitcoin4u.ca/security/ # # In scope for a bounty: a demonstrated vulnerability that leaks customer # information, grants unauthorized access, escalates privilege, or otherwise # allows a secured resource to be manipulated or compromised. # # Not normally rewarded: best-practice or hardening advice, missing headers # or recommended configuration, informational findings, automated scanner # output, and theoretical issues with no working exploit or evidence of real # risk. Reports of that kind are still read, and still welcome. # # Please include: the affected URL or endpoint, the steps to reproduce, the # impact you were able to demonstrate, and any request/response captures, # screenshots or proof-of-concept code needed to verify the finding. Test # only against accounts and data you own, and never against a Bitcoin4U ATM, # another customer's account, or our production funds. # # Please do not open a GitHub issue, post publicly, or contact support for a # security report - use the Contact address, and give us a reasonable window # to remediate before disclosure. Contact: mailto:security@bitcoin4u.ca Expires: 2028-09-19T00:00:00.000Z Preferred-Languages: en Canonical: https://bitcoin4u.ca/.well-known/security.txt Policy: https://bitcoin4u.ca/security/