This policy applies to any vulnerabilities you have discovered and are considering reporting to us. We are ‘TrilbyTV’, a product made by Trilby Multimedia Limited. We recommend reading this policy fully before you report a vulnerability and always acting in compliance with it.
We value those who take the time and effort to report security vulnerabilities. We are grateful that you share them with us while guaranteeing our best efforts to remedy them at the earliest. We do NOT offer bug bounties or payment of any kind. However, we guarantee plenty of good karma and our ever-lasting thanks.
Reporting
If you believe you have found a security vulnerability, please submit your report by email to security@trilbytv.co.uk.
In your report please include details of:
- The problem summary.
- A PoC or a breakdown of how the issue can be replicated.
- The operating system name and version, as well as the web browser name and text that you used to reproduce the issue.
What to expect
After you have submitted your report, it will be triaged and we aim to react promptly. We aim to resolve critical incidents within 48 working hours, lower priority issues will be usually be resolved within 5 working days. For reports that relate to an issue we are already aware of, or where we do not believe a vulnerability exists, we will not routinely follow up by email. If we require further details from you we will get in touch. We do NOT offer bug bounties or payment of any kind.
Guidance
This policy is applicable to trilbytv.co.uk, trilby.co.uk and trilby.uk, any subdomains.
You must not:
- Break any applicable laws or regulations.
- Access unnecessary, excessive or significant amounts of data.
- Continue the test if any personal data (other than your own) is encountered.
- Modify data in TrilbyTV’s systems or services.
- Use high-intensity invasive or destructive scanning tools to find vulnerabilities.
- Attempt or report any form of denial of service, e.g. overwhelming a service with a high volume of requests.
- Disrupt TrilbyTV’s services or systems.
- Submit reports detailing non-exploitable vulnerabilities, or reports indicating that the services do not fully align with “best practice”, for example, missing security headers.
- Social engineer, ‘phish’ or physically attack TrilbyTV’s staff or infrastructure.
- Demand financial compensation in order to disclose any vulnerabilities.
You must always:
- Comply with data protection rules and must not violate the privacy of TrilbyTV’s users, staff, contractors, services or systems. You must not, for example, share, redistribute or fail to properly secure data retrieved from the systems or services.
- Securely delete all data retrieved during your research as soon as it is no longer required or within 30 days of the vulnerability being resolved, whichever occurs first (or as otherwise required by data protection law).
Legalities
This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause TrilbyTV or partner companies to be in breach of any legal obligations.