Last Updated: August 28, 2026
Smart Business System takes the security of our platform and customer data seriously. We welcome reports from security researchers who discover potential vulnerabilities in good faith.
[PLACEHOLDER: Add company commitment statement — e.g., "We commit to acknowledging your report within X business days and working with you to resolve confirmed issues."]
Please send vulnerability reports to:
[Security Report] — Brief descriptionYour report should include:
| Action | Timeline |
|---|---|
| Acknowledgement of report | [PLACEHOLDER: e.g., within 3 business days] |
| Confirm validity of vulnerability | [PLACEHOLDER: e.g., within 10 business days] |
| Issue resolved and reporter notified | [PLACEHOLDER: e.g., within 90 days depending on severity] |
[PLACEHOLDER: List what systems/domains are in scope, e.g., app.smartbusinesses360.com and any subdomains.]
The following are not considered valid vulnerabilities:
[PLACEHOLDER: Add safe harbour statement — e.g., "We will not take legal action against researchers who report vulnerabilities in good faith following this policy, and we will not share your personal information with law enforcement without your consent."]
[PLACEHOLDER: Specify whether a bug bounty program exists, and if so, the rewards structure. If no bounty exists, state that clearly — e.g., "We currently do not offer monetary rewards, but we will publicly credit you with your permission."]