governance

Vulnerability Reporting

Detailed guidance on reporting security vulnerabilities to BodyFit and what happens after you submit a report.

v1.0 Updated 4 Aug 2026

Submission Process

Submit vulnerability reports to security@bodyfit.mi7z.com. Include: a clear description of the vulnerability, reproduction steps, potential impact, and any suggested remediation. PGP-encrypted email is supported on request. We triage reports within 48 hours.

Triage & Investigation

Our security team triages each report by severity. We reproduce the issue, assess impact, and assign a priority. High-severity vulnerabilities affecting user data or platform integrity are addressed immediately. We keep reporters informed throughout the process.

Resolution & Disclosure

Once fixed, we notify the reporter and, where appropriate, publish details in our Transparency Reports. We request that reporters allow us time to fix and deploy before any public disclosure. Coordinated disclosure benefits everyone.

Recognition

We credit security researchers who report valid vulnerabilities (with their permission) in our transparency reports. We are building a recognition programme and may offer reward points for significant contributions to BodyFit’s security.

Related Pages

Still need help?

Our support team is here to help. Reach out and we will get back to you within one business day.