governance

Responsible Disclosure

If you find a security vulnerability in BodyFit, we want to hear from you. Our responsible disclosure programme ensures reports are handled respectfully.

v1.0 Updated 4 Aug 2026

How to Report

Email security@bodyfit.mi7z.com with details of the vulnerability: what you found, steps to reproduce, and potential impact. Please do not publicly disclose the vulnerability until we have had time to investigate and fix it. We acknowledge reports within 48 hours.

What We Ask

We ask researchers to act in good faith: avoid accessing or modifying other users’ data, avoid disrupting service, and give us reasonable time to fix the issue before public disclosure. We will not take legal action against good-faith reports that respect these guidelines.

What We Provide

We acknowledge all reports, investigate promptly, and keep reporters updated on progress. We credit researchers in our transparency reports (with permission). While we do not currently offer monetary rewards, we may provide reward points and public recognition for significant findings.

Out of Scope

Reports about third-party services we use, self-XSS, clickjacking on non-sensitive pages, or issues requiring unlikely user interaction may be considered out of scope. We will explain our reasoning if we determine a report is out of scope.

Related Pages

Still need help?

Our support team is here to help. Reach out and we will get back to you within one business day.