If you think you have found a security problem in Finocket — a way to see someone else's data, a page that lets you do something you should not be able to, a link that works when it should have expired — please tell us before you tell anyone else.
Where to send it
Email support@dmstfy.com. The same address is published at /.well-known/security.txt in the format security researchers expect, and the full policy is at Security & Responsible Disclosure.
What to tell us
- What you did, step by step, and what happened instead of what you expected.
- The screen, link or address involved.
- Roughly when it happened, so we can find it in our logs.
- A screenshot if you have one — but see the warning below.
What happens next
- We acknowledge your email.
- We tell you whether we think it is a real vulnerability, and why.
- We keep you updated while we fix it, and tell you when it is fixed.
- We credit you if you would like that, and stay quiet about you if you would not.
There is no paid bug-bounty programme. We would rather say so plainly than let you spend a weekend on it expecting a reward that is not there.
If it is your account rather than a bug
If you think someone else has got into your account — an unfamiliar sign-in, entries you did not make — that is urgent and different. Change your password first, then write to us with roughly when you noticed. Security alerts about new sign-ins and password changes are the one kind of notification that cannot be switched off, so check those too. See Notifications.
Please do not
- Run load or denial-of-service tests. Real businesses invoice and file returns through this service; taking it down is not a demonstration, it is an outage for them.
- Phish our staff or try to talk your way into an account.
- Post it publicly first. Give us a reasonable chance to fix it.
Follow that and we treat your research as authorised: we will work with you and will not pursue legal action over it.
