Responsible Disclosure Process

Last updated: August 4, 2026

At MoeGo, protecting our customers' data and maintaining their trust is one of our highest priorities. Security is a shared responsibility, and we welcome good-faith contributions from the security research community.

Our Vulnerability Disclosure Program is a voluntary, community-driven security initiative. If you discover a potential security vulnerability affecting MoeGo, we encourage you to report it responsibly in accordance with this policy.

No Rewards or Compensation

MoeGo does not currently offer monetary rewards, gifts, credits, services, public recognition, or any other form of compensation for vulnerability reports.

Participation is entirely voluntary. Submitting a report does not create any entitlement to payment, compensation, employment, engagement, or other reward from MoeGo. MoeGo may change this policy in the future, but no future reward or recognition is promised or implied. Any future public recognition will require the researcher's prior consent.

Our Commitment

If you report a valid security vulnerability in good faith and in accordance with this policy, we commit to:

  • Treating you with respect and professionalism
  • Handling your report and personal information confidentially, subject to applicable legal and operational requirements
  • Investigating and validating your findings responsibly
  • Working to address confirmed vulnerabilities and protect our users
  • Prioritizing remediation based on the severity and impact of the issue

We appreciate your voluntary efforts to help keep MoeGo and our customers safe.

Scope

This policy applies only to systems owned and controlled by MoeGo under the following domains:

  • moego.pet
  • *.moego.pet

Systems or services operated by third parties are not in scope, even if they use a MoeGo domain. If you are unsure whether a system is in scope, contact us at Security@moego.pet before conducting any testing.

Security Testing Requirements

When conducting security testing:

  • Include x-moegosec-vdp: <your-email-address> in every request sent directly to an in-scope MoeGo system. Use an email address that you own and that matches the contact information in your report.
  • Test only systems expressly included in this policy.
  • Use only accounts and data that you own or are explicitly authorized to use.
  • Limit testing to what is necessary to identify and confirm the vulnerability.
  • Do not access, modify, copy, retain, or delete personal data, customer data, credentials, or other information that does not belong to you.
  • If you encounter sensitive information or unintended access, stop testing immediately, do not download or further access the information, and notify us promptly with only the minimum details needed to locate the issue.
  • Avoid actions that could disrupt MoeGo's services or affect other users.

The header requirement does not expand the systems, data, or activities authorized by this policy.

Reporting Guidelines

When investigating or reporting a vulnerability:

  • Do not exploit the vulnerability beyond what is necessary to confirm its existence.
  • Do not perform actions that degrade, interrupt, or deny access to our services.
  • Do not use social engineering, phishing, physical intrusion, threats, or extortion.
  • Do not publicly disclose the vulnerability without MoeGo's prior written permission.

Your report should include:

  • A clear and concise description of the issue
  • The affected system, endpoint, or feature
  • Steps required to reproduce the vulnerability
  • A description of its potential impact
  • Relevant redacted screenshots, logs, or proof-of-concept code, if available
  • Your current contact information so we can follow up

Do not include unredacted personal data, customer data, credentials, or other sensitive information in a report.

Submit your report to Security@moego.pet.

Out of Scope

The following activities and issues are outside the scope of this program:

  • Denial-of-service attacks or resource exhaustion
  • Social engineering or phishing involving staff, users, or partners
  • Physical security testing
  • Vulnerabilities in third-party systems not owned or controlled by MoeGo
  • Clickjacking on pages without sensitive interactions
  • Missing security headers or TLS best practices without demonstrated security impact
  • Rate-limiting or brute-force issues affecting non-sensitive endpoints
  • Automated scanning or fuzzing that generates excessive traffic
  • Reports based solely on automated scanner output without a demonstrated, reproducible security impact

If you are unsure whether an activity or issue is in scope, contact Security@moego.pet before proceeding.

Safe Harbor

MoeGo supports good-faith security research conducted strictly in accordance with this policy.

To the extent permitted by applicable law, MoeGo does not intend to initiate legal action solely because a researcher performed security testing that strictly complies with this policy. This statement is limited to MoeGo's own actions and does not bind third parties, provide legal immunity, waive any rights, or authorize violations of applicable law.

This policy authorizes only the limited research described here. It does not authorize access to systems, accounts, or data outside the scope, or any activity that violates this policy, harms MoeGo or another party, disrupts services, or involves unauthorized data access. MoeGo reserves all rights and may take appropriate action in response to violations, unauthorized activity, or applicable legal requirements.

To remain eligible for this limited Safe Harbor, you must:

  • Act in good faith
  • Comply with this policy and all applicable laws
  • Avoid harm to MoeGo, our customers, our employees, and other parties
  • Stop testing and notify us promptly if sensitive data or unintended access is encountered
  • Give MoeGo a reasonable opportunity to investigate and remediate the issue before any disclosure

Disclosure Policy

Do not publicly disclose a suspected or confirmed vulnerability, including after remediation, without MoeGo's prior written permission. This prohibition has no automatic expiry.

Send reports and relevant details to Security@moego.pet. Please include enough information for us to reproduce and assess the issue.

We will respond as soon as reasonably practicable, but this policy does not provide a specific response or remediation timeline.

By submitting a report, you acknowledge that participation is voluntary and that MoeGo does not currently provide or promise any reward, compensation, or public recognition.