Detailed guidance on reporting security vulnerabilities to BodyFit and what happens after you submit a report.
Submit vulnerability reports to security@bodyfit.mi7z.com. Include: a clear description of the vulnerability, reproduction steps, potential impact, and any suggested remediation. PGP-encrypted email is supported on request. We triage reports within 48 hours.
Our security team triages each report by severity. We reproduce the issue, assess impact, and assign a priority. High-severity vulnerabilities affecting user data or platform integrity are addressed immediately. We keep reporters informed throughout the process.
Once fixed, we notify the reporter and, where appropriate, publish details in our Transparency Reports. We request that reporters allow us time to fix and deploy before any public disclosure. Coordinated disclosure benefits everyone.
We credit security researchers who report valid vulnerabilities (with their permission) in our transparency reports. We are building a recognition programme and may offer reward points for significant contributions to BodyFit’s security.
Responsible Disclosure
If you find a security vulnerability in BodyFit, we want to hear from you. Our responsible disclosure programme ensures reports are handled respectfully.
Security Programme
BodyFit’s Security Programme protects user data and platform integrity through preventive, detective, and responsive security controls.
Transparency Reports
BodyFit publishes transparency information about our practices, requests, and assurance activities to build and maintain user trust.
System Security
Technical details of how BodyFit secures our platform, infrastructure, and user data against unauthorised access and threats.