Vulnerability Disclosure Policy

Last updated: 16 April 2026

CaptiFi Limited takes the security of our systems and customer data seriously. We appreciate the work of security researchers who help us keep our platform safe. This policy outlines how to report vulnerabilities responsibly.

Reporting a Vulnerability

If you believe you have found a security vulnerability in any CaptiFi-owned service, please report it to us by emailing:

accounts@captifi.io

Please include the following in your report:

  • A description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • Any supporting evidence such as screenshots, URLs, or proof-of-concept code
  • Your name and contact details (optional, but helpful for follow-up)

What We Ask

  • Give us reasonable time to investigate and address the issue before disclosing it publicly
  • Do not access, modify, or delete data belonging to other users
  • Do not perform actions that could degrade our services (e.g. denial of service attacks)
  • Do not use automated scanning tools in a way that generates excessive traffic
  • Act in good faith and comply with all applicable laws

What to Expect

  • We will acknowledge receipt of your report within 3 business days
  • We will investigate the issue and aim to provide a status update within 10 business days
  • We will notify you when the vulnerability has been resolved
  • We will not take legal action against researchers who follow this policy in good faith

Bug Bounty

We do not currently operate a paid bug bounty programme. However, we genuinely appreciate responsible disclosure and will credit researchers (with permission) for valid findings.

Scope

This policy applies to the following CaptiFi-owned domains and services:

  • captifi.io (and all subdomains)
  • The CaptiFi captive portal platform

Third-party services, integrations, and platforms not operated by CaptiFi are out of scope.