Travel
By continuing to use the Platform, you agree to cookies and similar technologies. If you do not agree, discontinue use.
VIDI Privacy Policy
·
VIDI Cookie Policy
By continuing to use the Platform, you agree to cookies and similar technologies. If you do not agree, discontinue use.
VIDI Privacy Policy
·
VIDI Cookie Policy
Legal information
Security Policy / Responsible Disclosure Policy
Version 2026-05-17 · effective 2026-05-17
Last Updated: 2026-05-17
This Security Policy & Responsible Disclosure Policy (“Policy”) applies to all websites, applications, APIs, subdomains, mobile applications, infrastructure, digital products, and related services operated under the VIDI brand, including but not limited to *.vidi.one (collectively, the “Platform”).
By interacting with the Platform for security research, vulnerability reporting, testing, or related activities, individuals acknowledge and agree to this Policy.
1. Purpose of this Policy
VIDI values responsible security research and encourages good-faith reporting of legitimate security vulnerabilities that may affect the confidentiality, integrity, or availability of the Platform.
This Policy establishes:
•
responsible disclosure expectations;
•
permitted and prohibited testing activities;
•
reporting procedures;
•
security communication standards;
•
enforcement rights.
VIDI reserves the right to modify, suspend, or terminate this Policy at any time.
2. Scope
This Policy applies to:
•
websites;
•
subdomains;
•
APIs;
•
mobile applications;
•
infrastructure;
•
backend systems;
•
cloud environments;
•
authentication systems;
•
digital products;
•
services operated under *.vidi.one.
Third-party services, providers, payment systems, cloud providers, and external integrations may be excluded from scope unless explicitly stated otherwise.
3. Responsible Disclosure
Individuals acting in good faith may report potential vulnerabilities to VIDI.
Responsible disclosure generally means:
•
avoiding harm to users or systems;
•
avoiding disruption of services;
•
avoiding unauthorized access to data;
•
avoiding privacy violations;
•
reporting findings privately;
•
allowing reasonable remediation time before disclosure;
•
avoiding exploitation beyond what is necessary to demonstrate the issue.
Public disclosure before remediation or authorization may be considered unauthorized activity.
4. Prohibited Activities
The following activities are strictly prohibited without explicit written authorization from VIDI:
•
destructive testing;
•
denial-of-service attacks;
•
distributed denial-of-service attacks (DDoS);
•
service disruption;
•
malware deployment;
•
ransomware testing;
•
phishing campaigns;
•
social engineering;
•
credential stuffing;
•
password attacks;
•
brute-force attacks;
•
scraping;
•
automated harvesting;
•
excessive automated scanning;
•
exploitation of vulnerabilities;
•
unauthorized access;
•
privilege escalation;
•
account takeover testing;
•
data extraction;
•
downloading user information;
•
modifying data;
•
persistence mechanisms;
•
bypassing authentication systems;
•
bypassing rate limits;
•
interfering with infrastructure;
•
targeting third-party providers;
•
accessing financial systems;
•
accessing payment information;
•
accessing private communications.
Testing that impacts stability, performance, privacy, availability, or integrity of the Platform may be treated as unauthorized activity.
5. Automated Scanning Restrictions
VIDI may restrict or prohibit:
•
automated scanning;
•
mass scanning;
•
aggressive probing;
•
automated exploitation;
•
scraping during testing;
•
automated credential attacks;
•
vulnerability enumeration;
•
high-volume requests.
VIDI reserves the right to block:
•
IP addresses;
•
devices;
•
automated agents;
•
suspicious traffic;
•
testing infrastructure.
6. Reporting Vulnerabilities
Security vulnerabilities may be reported to:
security@vidi.one
Reports should include:
•
description of the issue;
•
affected systems;
•
reproduction steps;
•
proof-of-concept details where appropriate;
•
potential impact;
•
contact information.
VIDI may request:
•
additional information;
•
clarification;
•
verification steps;
•
responsible disclosure cooperation.
7. No Guarantee of Compensation
VIDI does not guarantee:
•
bug bounty programs;
•
financial rewards;
•
public recognition;
•
compensation;
•
response timelines;
•
remediation timelines.
Any rewards, acknowledgments, or discretionary compensation may be provided solely at VIDI’s discretion.
8. Enforcement Rights
VIDI reserves the right to:
•
investigate activity;
•
preserve logs and evidence;
•
restrict access;
•
suspend accounts;
•
block IP addresses;
•
block devices;
•
terminate services;
•
report activity to providers or authorities;
•
pursue legal remedies.
VIDI may determine whether activity exceeds authorized or acceptable research at its sole discretion.
9. No Authorization for Broader Activity
This Policy does not authorize:
•
persistent testing;
•
ongoing monitoring;
•
unrestricted scanning;
•
exploitation;
•
data collection;
•
privacy violations;
•
circumvention of security measures;
•
testing against third-party providers;
•
unauthorized automation.
Failure to comply with this Policy may result in:
•
account restrictions;
•
legal claims;
•
service bans;
•
reporting to authorities.
10. Third-Party Systems
Certain Platform functionality may rely on:
•
cloud providers;
•
payment processors;
•
analytics providers;
•
infrastructure vendors;
•
APIs;
•
third-party integrations.
This Policy does not grant authorization to test, scan, or target third-party systems.
Researchers remain responsible for complying with third-party policies and applicable laws.
11. Limitation of Liability
To the maximum extent permitted by law, VIDI shall not be liable for:
•
testing-related losses;
•
interrupted access;
•
blocked traffic;
•
automated restrictions;
•
enforcement actions;
•
service interruptions;
•
data access denial;
•
rejected reports.
Individuals engaging in security research assume all associated risks.
12. International Compliance
Researchers and users are responsible for compliance with:
•
local laws;
•
cybersecurity regulations;
•
export restrictions;
•
sanctions regulations;
•
anti-hacking laws;
•
privacy laws.
Certain testing activities may be prohibited in specific jurisdictions.
13. Changes to this Policy
VIDI may modify this Policy at any time without prior notice.
Updated versions become effective upon publication on the Platform.
Continued interaction with the Platform constitutes acceptance of updated versions.
14. Language
In the event of inconsistencies between translated versions of this Policy, the English-language version shall control unless otherwise required by applicable law.
15. Contact Information
Security Reports: security@vidi.one Legal Requests: legal@vidi.one Abuse Reports: abuse@vidi.one General Support: support@vidi.one
Legal information
VIDI
Travel
© 2026 VIDI. All rights reserved
All information is for demonstration purposes only and is a work of fiction; it is not investment advice. Terms and fees may differ from actual bank tariffs; any resemblance is purely coincidental.
support@vidi.one
City — VIDI Travel

City — VIDI Travel

Flights, eSIM, tours, and travel services for the city.

Security Policy / Responsible Disclosure Policy