Vulnerability Disclosure Policy
This vulnerability disclosure policy explains how to report security issues in Prime My Body products and services, and how we handle those reports.
Scope
In scope: the public Prime My Body platform site, tenant studio experiences we operate, BFF APIs under our control, and authentication or authorization flaws that could affect other members or tenants.
Out of scope: social networks we integrate with (Meta, TikTok, etc.), third-party AI providers, denial-of-service volume testing, physical security, and social engineering of employees or customers.
How to report
Submit reports via our security team notify page: https://advantageai.brightlite.cloud/securityteam/notify.
Include steps to reproduce, affected URLs or APIs, impact, and any proof-of-concept that does not destroy data or disrupt production.
Safe harbor
If you make a good-faith effort to follow this policy, avoid privacy violations and service disruption, and report promptly, we will not pursue legal action related to that research.
Our commitments
- Acknowledge receipt within 5 business days when contact details are provided.
- Keep you informed of remediation status when feasible.
- Credit you in our acknowledgments if you wish, after a fix is available.
Related
- security.txt (RFC 9116)
- Security hiring
- Privacy Policy