Systems in scope
This policy authorizes good-faith security testing only against digital services owned and controlled by For Safety Group Inc. at:
- https://www.by4si.com and https://by4si.com;
- https://presence.by4si.com;
- https://intelligence.by4si.com;
- public API endpoints served under those hostnames.
Third-party products, provider infrastructure, unrelated domains, employee devices, partner systems and physical Presence hardware are out of scope unless 4SI gives separate written authorization. A third-party component visible through a 4SI service does not authorize testing the provider itself.
Rules for good-faith research
Use the minimum interaction and data necessary to demonstrate a vulnerability. Stop and report immediately if you encounter personal data, credentials, private keys, confidential partner information, non-public research, physical-security details or evidence of active exploitation.
Do not:
- access, modify, retain or disclose another person’s data beyond the minimum proof;
- use social engineering, phishing, physical intrusion or attacks against employees, customers or partners;
- perform denial of service, resource exhaustion, destructive testing, spam or high-volume automated scanning;
- introduce persistent access, malware or data-exfiltration tooling;
- test payment providers, identity providers, email providers, hosting infrastructure or another third party outside the listed scope;
- violate law or demand payment, threaten disclosure or withhold necessary remediation information.
Safe harbor
If you make a good-faith effort to follow this policy, 4SI considers your research authorized for purposes of applicable anti-circumvention and computer-misuse laws and will not initiate legal action against you for that research. If a third party brings legal action and you complied with this policy, 4SI will make your compliance known where appropriate.
This safe harbor does not bind third parties, authorize access to their systems, waive legal privilege or protect conduct that is malicious, reckless, outside scope or unlawful. If you are uncertain whether an action is permitted, ask before proceeding.
How to report
Email contact@by4si.com with the subject “Responsible Disclosure Report.” Include:
- the affected hostname, URL, feature and approximate time observed;
- a concise description, impact and prerequisites;
- reproduction steps and the minimum evidence needed to validate;
- whether any personal, confidential or security-sensitive data was encountered;
- your preferred contact method and any disclosure timeline you propose.
Do not place live credentials, large datasets or unnecessary personal data in the initial email. Start with a minimal description if the report concerns sensitive architecture or physical security so a controlled channel can be established.
What to expect
- 4SI aims to acknowledge a credible report within five business days.
- 4SI aims to provide an initial triage or request for clarification within ten business days.
- Remediation priority and timing depend on exploitability, impact, affected systems and coordination needs.
- 4SI will seek to keep the reporter informed at meaningful milestones.
Please coordinate public disclosure with 4SI. Unless earlier disclosure is required by law or necessary to address imminent harm, allow remediation or 90 calendar days from a sufficiently detailed initial report, whichever occurs first. The parties may agree to a different timeline based on risk and dependency coordination.
This policy does not create a bug-bounty program or promise payment. Recognition may be considered only with the reporter’s consent.
Useful reports
High-value reports demonstrate a material security consequence, such as authentication or authorization bypass, exposure of protected information, remote code execution, injection, account takeover, privilege escalation, meaningful cross-tenant access or a practical integrity failure.
Automated scanner output without validation, missing best-practice headers without demonstrated impact, self-XSS, clickjacking on pages without sensitive actions and rate-limit observations without a security consequence may not receive individual follow-up.