Security Policy
Responsible Disclosure
If you discover a security vulnerability in Floopy, we encourage you to report it responsibly. We will investigate all legitimate reports and work to address them promptly.
To report a vulnerability, please contact us at support@buildme.uz or via Telegram at @floopy_support.
Scope
This policy applies to all Floopy-owned applications and services, including buildme.uz and all subdomains, the API, and related infrastructure.
Our Commitments
- We will respond to your report within 5 business days
- We will keep you informed of our progress
- We will not pursue legal action for good-faith research
- We will credit you for your discovery (if desired)
Out of Scope
- Self-XSS or attacks requiring social engineering
- Missing security headers not exploitable on their own
- Rate limiting concerns on non-authenticated endpoints
- Disclosure of public or non-sensitive information