This Security Policy & Responsible Disclosure Policy (“Policy”) applies to all websites, applications, APIs, subdomains, mobile applications, infrastructure, digital products, and related services operated under the VIDI brand, including but not limited to *.vidi.one (collectively, the “Platform”).
By interacting with the Platform for security research, vulnerability reporting, testing, or related activities, individuals acknowledge and agree to this Policy.
1. Purpose of this Policy
VIDI values responsible security research and encourages good-faith reporting of legitimate security vulnerabilities that may affect the confidentiality, integrity, or availability of the Platform.
•
responsible disclosure expectations;
•
permitted and prohibited testing activities;
•
security communication standards;
VIDI reserves the right to modify, suspend, or terminate this Policy at any time.
2. Scope
•
services operated under *.vidi.one.
Third-party services, providers, payment systems, cloud providers, and external integrations may be excluded from scope unless explicitly stated otherwise.
3. Responsible Disclosure
Individuals acting in good faith may report potential vulnerabilities to VIDI.
Responsible disclosure generally means:
•
avoiding harm to users or systems;
•
avoiding disruption of services;
•
avoiding unauthorized access to data;
•
avoiding privacy violations;
•
reporting findings privately;
•
allowing reasonable remediation time before disclosure;
•
avoiding exploitation beyond what is necessary to demonstrate the issue.
Public disclosure before remediation or authorization may be considered unauthorized activity.
4. Prohibited Activities
The following activities are strictly prohibited without explicit written authorization from VIDI:
•
denial-of-service attacks;
•
distributed denial-of-service attacks (DDoS);
•
excessive automated scanning;
•
exploitation of vulnerabilities;
•
account takeover testing;
•
downloading user information;
•
bypassing authentication systems;
•
interfering with infrastructure;
•
targeting third-party providers;
•
accessing financial systems;
•
accessing payment information;
•
accessing private communications.
Testing that impacts stability, performance, privacy, availability, or integrity of the Platform may be treated as unauthorized activity.
5. Automated Scanning Restrictions
VIDI may restrict or prohibit:
•
automated credential attacks;
•
vulnerability enumeration;
VIDI reserves the right to block:
6. Reporting Vulnerabilities
Security vulnerabilities may be reported to:
•
description of the issue;
•
proof-of-concept details where appropriate;
•
responsible disclosure cooperation.
7. No Guarantee of Compensation
Any rewards, acknowledgments, or discretionary compensation may be provided solely at VIDI’s discretion.
8. Enforcement Rights
VIDI reserves the right to:
•
preserve logs and evidence;
•
report activity to providers or authorities;
VIDI may determine whether activity exceeds authorized or acceptable research at its sole discretion.
9. No Authorization for Broader Activity
This Policy does not authorize:
•
circumvention of security measures;
•
testing against third-party providers;
Failure to comply with this Policy may result in:
•
reporting to authorities.
10. Third-Party Systems
Certain Platform functionality may rely on:
•
third-party integrations.
This Policy does not grant authorization to test, scan, or target third-party systems.
Researchers remain responsible for complying with third-party policies and applicable laws.
11. Limitation of Liability
To the maximum extent permitted by law, VIDI shall not be liable for:
Individuals engaging in security research assume all associated risks.
12. International Compliance
Researchers and users are responsible for compliance with:
•
cybersecurity regulations;
Certain testing activities may be prohibited in specific jurisdictions.
13. Changes to this Policy
VIDI may modify this Policy at any time without prior notice.
Updated versions become effective upon publication on the Platform.
Continued interaction with the Platform constitutes acceptance of updated versions.
14. Language
In the event of inconsistencies between translated versions of this Policy, the English-language version shall control unless otherwise required by applicable law.
15. Contact Information
Security Reports: security@vidi.one Legal Requests: legal@vidi.one Abuse Reports: abuse@vidi.one General Support: support@vidi.one