报告范围 / What to report
可报告未经授权访问、身份验证绕过、敏感数据暴露、支付流程篡改、跨站脚本、注入和其他可复现安全问题。请提供受影响路径、复现步骤、影响和最小必要证据。
Report unauthorised access, authentication bypass, sensitive-data exposure, payment-flow tampering, XSS, injection and other reproducible issues with affected path, steps, impact and minimum necessary evidence.
安全研究边界 / Research safe harbour
在法律允许且善意、最小影响的前提下,不访问他人数据、不改变或删除数据、不进行拒绝服务、社工、物理测试、自动大规模扫描或公开未修复细节。无法安全继续时立即停止并报告。
Act lawfully, in good faith and with minimal impact: do not access others' data, alter/delete data, perform denial-of-service, social engineering, physical tests, mass automated scanning or disclose unpatched details. Stop and report if safe continuation is not possible.
响应 / Response
经核验的报告会获得确认、风险分级和修复协调;响应时间随严重性和证据完整度而异。不承诺奖金,任何奖励需书面确认。
Validated reports receive acknowledgement, severity assessment and remediation coordination. Timing depends on severity and evidence. No bounty is promised unless confirmed in writing.
安全承诺 / Security statement
采用与风险相称的访问控制、加密、日志、备份、依赖管理和事件响应。安全措施降低风险但不构成绝对安全保证;发生依法需要通知的事件时按适用要求处理。
Risk-proportionate access controls, encryption, logging, backup, dependency management and incident response are used. These reduce risk without guaranteeing absolute security; legally notifiable incidents are handled under applicable rules.