Yokahu is a trading name of McCosh Holdings Ltd. In this Vulnerability Disclosure Policy, references to Yokahu are to McCosh Holdings Ltd. We take the security of our customer's confidential information extremely seriously. The disclosure of security vulnerabilities helps us protect the security and privacy of our users.
We want to hear from security researchers who have information related to suspected security vulnerabilities of any Yokahu services exposed to the internet. We value your work and are committed to working with you. Thank you in advance for your contribution.
We require that all researchers:
We ask that you do the following in conducting your research: contact us immediately if you inadvertently encounter user data, and do not view, alter, save, store, transfer, or otherwise access the data; act in good faith to avoid privacy violations, destruction of data, and interruption or degradation of our services; and comply with all applicable laws.
In conducting your research under this policy you are not permitted to carry out any of the following: spamming forms or scanning applications through automated vulnerability scanners; publicly disclosing a vulnerability without giving us a reasonable amount of time to respond; accessing or modifying our data or our users' data without explicit permission of the relevant owner; Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks; or attacks on third party services.
If you follow these guidelines when reporting an issue to us, we commit to: not pursue or support any legal action related to your research for what we consider to be accidental, good faith violations of this policy; work with you to understand and resolve the issue quickly, including an initial confirmation of your report within 72 hours of submission; take reasonable steps to make known that your actions were conducted in compliance with this policy if legal action is initiated by a third party against you; and not attempt to silence researchers who report vulnerabilities to us.
https://cat-risk.com
Any services not explicitly mentioned or hosted by third party providers are excluded from scope. These services include payment services such as Stripe; KYC, AML and identity checking services; and the presence or absence of SPF records.
In the interest of the safety of our users, staff, the Internet at large and you as a security researcher, the following test types and vulnerabilities are excluded from scope: findings from physical testing such as office access; findings derived primarily from social engineering (e.g. phishing, vishing); UI and UX bugs and spelling mistakes; passwords, emails and user accounts (such as email verification, reset link expiration and password complexity); attacks requiring physical access to a user's device; missing security headers which do not lead directly to a vulnerability; missing best practices; self-XSS that does not lead to leakage of confidential information; host header injections that do not lead to leakage of confidential information; use of a known-vulnerable library without evidence of exploitability; reports from automated tools or scans; reports of spam; clickjacking or tapjacking; vulnerabilities affecting users of outdated browsers or platforms; content spoofing vulnerabilities; absence of rate limiting (unless related to authentication); and network level Denial of Service vulnerabilities.
If you believe you've found a security vulnerability in one of our products or platforms please send it to us by emailing security@yokahu.co. All communication should be PGP encrypted; our public keys can be found at https://keys.openpgp.org (search for security@yokahu.co or admin@yokahu.co).
Please include the following details with your report: a description of the location and potential impact of the vulnerability; whether or not, in your opinion, customer data is or could be exposed as a result; a detailed description of the steps required to reproduce the vulnerability (POC scripts, screenshots, and compressed screen captures are all helpful); and optionally, recommendations for remediation if you are aware of how to fix the vulnerability.
Things we do not want to receive from you: personally identifiable information (PII) and credit card holder data.
By submitting your report, you agree not to publicly disclose the vulnerability until Yokahu agrees to a public disclosure; you agree to keep all communication with Yokahu confidential; you represent the report is original to you; and you allow Yokahu the unconditional ability to use, distribute, and/or disclose information provided in your report.