If you find a security vulnerability in BodyFit, we want to hear from you. Our responsible disclosure programme ensures reports are handled respectfully.
Email security@bodyfit.mi7z.com with details of the vulnerability: what you found, steps to reproduce, and potential impact. Please do not publicly disclose the vulnerability until we have had time to investigate and fix it. We acknowledge reports within 48 hours.
We ask researchers to act in good faith: avoid accessing or modifying other users’ data, avoid disrupting service, and give us reasonable time to fix the issue before public disclosure. We will not take legal action against good-faith reports that respect these guidelines.
We acknowledge all reports, investigate promptly, and keep reporters updated on progress. We credit researchers in our transparency reports (with permission). While we do not currently offer monetary rewards, we may provide reward points and public recognition for significant findings.
Reports about third-party services we use, self-XSS, clickjacking on non-sensitive pages, or issues requiring unlikely user interaction may be considered out of scope. We will explain our reasoning if we determine a report is out of scope.
Vulnerability Reporting
Detailed guidance on reporting security vulnerabilities to BodyFit and what happens after you submit a report.
Security Programme
BodyFit’s Security Programme protects user data and platform integrity through preventive, detective, and responsive security controls.
System Security
Technical details of how BodyFit secures our platform, infrastructure, and user data against unauthorised access and threats.
Transparency Reports
BodyFit publishes transparency information about our practices, requests, and assurance activities to build and maintain user trust.