Дата последнего обновления: 2026-05-17
Настоящая Политика Security & Responsible Disclosure (“Политика”) применяется ко всем веб-сайтам, приложениям, API, поддоменам, мобильным приложениям, infrastructure, digital products и связанным сервисам, работающим под брендом VIDI, включая, помимо прочего, *.vidi.one (совместно — «Платформа»).
Любые лица, взаимодействующие с Платформой в целях security research, vulnerability reporting, testing или related activities, подтверждают согласие с настоящей Политикой.
1. Цель Политики
VIDI поддерживает responsible security research и encourages good-faith reporting legitimate security vulnerabilities, которые могут повлиять на confidentiality, integrity или availability Платформы.
Настоящая Политика устанавливает:
•
responsible disclosure expectations;
•
permitted и prohibited testing activities;
•
security communication standards;
VIDI оставляет за собой право modify, suspend или terminate настоящую Политику в любое время.
2. Scope
Настоящая Политика распространяется на:
•
services operated under *.vidi.one.
Third-party services, providers, payment systems, cloud providers и external integrations могут быть excluded from scope, если иное прямо не указано.
3. Responsible Disclosure
Лица, acting in good faith, могут сообщать VIDI о potential vulnerabilities.
Responsible disclosure обычно означает:
•
avoiding harm users или systems;
•
avoiding disruption services;
•
avoiding unauthorized access data;
•
avoiding privacy violations;
•
reporting findings privately;
•
предоставление reasonable remediation time before disclosure;
•
avoiding exploitation beyond what is necessary demonstrate issue.
Public disclosure до remediation или authorization может рассматриваться как unauthorized activity.
4. Prohibited Activities
Следующие activities строго запрещены без explicit written authorization от VIDI:
•
denial-of-service attacks;
•
distributed denial-of-service attacks (DDoS);
•
excessive automated scanning;
•
exploitation vulnerabilities;
•
account takeover testing;
•
downloading user information;
•
bypassing authentication systems;
•
interfering infrastructure;
•
targeting third-party providers;
•
accessing financial systems;
•
accessing payment information;
•
accessing private communications.
Testing, влияющий на stability, performance, privacy, availability или integrity Платформы, может рассматриваться как unauthorized activity.
5. Automated Scanning Restrictions
VIDI может restrict или prohibit:
•
automated credential attacks;
•
vulnerability enumeration;
VIDI оставляет за собой право block:
6. Reporting Vulnerabilities
Security vulnerabilities могут направляться на:
•
proof-of-concept details where appropriate;
•
responsible disclosure cooperation.
7. No Guarantee of Compensation
Любые rewards, acknowledgments или discretionary compensation могут предоставляться исключительно по усмотрению VIDI.
8. Enforcement Rights
VIDI оставляет за собой право:
•
preserve logs и evidence;
•
report activity providers или authorities;
VIDI вправе самостоятельно определять, превышает ли activity authorized или acceptable research.
9. No Authorization for Broader Activity
Настоящая Политика не authorizes:
•
circumvention security measures;
•
testing against third-party providers;
Failure comply настоящей Политике может привести к:
10. Third-Party Systems
Certain Platform functionality может rely on:
•
third-party integrations.
Настоящая Политика не предоставляет authorization на testing, scanning или targeting third-party systems.
Researchers самостоятельно обязаны соблюдать:
11. Ограничение ответственности
В максимальной степени, разрешенной законодательством, VIDI не несет ответственности за:
Лица, engaging in security research, принимают на себя все associated risks.
12. International Compliance
Researchers и users самостоятельно обязаны соблюдать:
•
cybersecurity regulations;
Certain testing activities могут быть prohibited в отдельных jurisdictions.
13. Изменения Политики
VIDI вправе изменять настоящую Политику в любое время без предварительного уведомления.
Updated versions вступают в силу после publication Platform.
Продолжение interaction с Платформой означает acceptance updated versions.
14. Язык
При расхождениях между переводами приоритет имеет английская версия, если иное не предусмотрено applicable law.
15. Контактная информация
Security Reports: security@vidi.one Legal Requests: legal@vidi.one Abuse Reports: abuse@vidi.one General Support: support@vidi.one