Skip to main content

Contact us

MyOffice Policy on Vulnerability Reporting and Disclosure

We are grateful to security researchers for their help in maintaining high standards of security and privacy for our customers.

Security is of utmost importance to us. We appreciate the discovery of potential vulnerabilities in our products and the reports they receive through MyOffice.

This policy outlines MyOffice's responsible approach to vulnerability discovery and reporting.

MyOffice does not have an active BugBounty program. No payments are made for vulnerabilities found.

If you discover a vulnerability in MyOffice products, please immediately email us at vulnerability@myoffice.team. Use PGP key to encrypt the email.

When reporting a vulnerability, please include the following:

  • Contact information. MyOffice specialists need to know how to contact you and how to address you to clarify information about the product vulnerability.
  • Product name and version, as well as the operating system version of the device on which the vulnerability was found.
  • A detailed description of the vulnerability so we can determine its nature and the scope of the problem.
  • Steps for reproducing the vulnerability so we can expedite its verification and mitigation.
  • Information about whether you plan to disclose information about the vulnerability to third parties.

MyOffice will analyze the information, take the necessary measures to fix the vulnerability as quickly as possible, and notify you of the results.

note

Please do not publish information about the vulnerability until it has been fixed by our team. This will reduce the risk of this information being shared with potential attackers.