Policies / Security and Vulnerability Disclosure
Security and Vulnerability Disclosure
Draft for legal review · updated 23 September 2026 · not yet effective
Report a vulnerability to info@24frames.co. Include the affected app version, page or endpoint; reproducible steps; the likely impact; and a safe way to contact you. Do not include another person's personal data or credentials.
Please test only accounts and data you control. Stop if you encounter someone else's information. Do not disrupt the service, flood endpoints, conduct phishing or social engineering, or test third-party systems such as Bunny, Resend, mobile operators or app stores. Report those systems to their operators. Coordinate public disclosure with us and follow applicable law.
We will triage good-faith reports and work to fix verified issues. We cannot promise a fixed acknowledgement or remediation deadline in this draft. We do not operate a paid bug bounty. No statement here waives legal rights or authorises unlawful testing.
The current security posture and limitations are described in Privacy Policy. If you think your account has been accessed without permission, revoke unfamiliar sessions under “Your devices” and email info@24frames.co. Contact address: 24 Frames Pty Ltd, Plot 91, Unit 2, Gaborone International Commerce Park, Gaborone, Botswana. Telephone: +267 77 064 028.