Security Disclosure Policy
Version: 1.0
Effective Date: September 12, 2026
Service Owner: FOP Gaitan Kyrylo Oleksandrovych
Website: https://taleino.com
Security Contact: [email protected]
1. Our Commitment to Security
1.1. Taleino takes the security and privacy of our customers, their personal information, and our platform infrastructure seriously.
1.2. We welcome responsible security research and encourage security researchers to report vulnerabilities that may affect Taleino, our customers, or our systems.
1.3. This Security Disclosure Policy describes the principles and procedures for responsibly reporting potential security vulnerabilities to Taleino.
1.4. This Policy is intended to provide a clear communication channel for security researchers and to encourage good-faith security testing that does not harm our users or systems.
2. Responsible Disclosure
2.1. We ask security researchers conducting testing against Taleino to:
- act in good faith and only for the purpose of identifying and reporting security vulnerabilities;
- avoid accessing, modifying, deleting, or exposing personal information belonging to other users;
- avoid actions that could affect the availability or reliability of Taleino;
- keep vulnerability details confidential until Taleino has had a reasonable opportunity to investigate and address the issue;
- provide sufficient information to reproduce and understand the reported vulnerability;
- comply with applicable laws and regulations.
2.2. Researchers who follow this Policy and conduct security research in good faith should contact us before taking any action that could potentially cause harm.
2.3. To report a potential vulnerability, please contact:
Email: [email protected]
Suggested subject:
[Security Report] Brief description of vulnerability
2.4. Please do not include passwords, payment card information, authentication credentials, or unnecessary personal information in a vulnerability report.
3. Scope
3.1. This Policy applies primarily to Taleino-controlled websites, applications, and services, including:
| System | Scope |
|---|---|
| Main website | https://taleino.com and Taleino pages hosted under the domain |
| Web application | Taleino functionality available to registered users |
| Subdomains | Taleino-controlled subdomains, where applicable |
| Backend services | Taleino-controlled backend systems and APIs, where publicly accessible |
3.2. The scope may change as Taleino introduces additional products, services, or infrastructure.
3.3. Out of scope:
- third-party websites, services, infrastructure, or applications that Taleino does not control;
- vulnerabilities in third-party software where Taleino's own implementation or configuration is not the cause of the vulnerability;
- social engineering or phishing attacks against Taleino employees, contractors, customers, or third parties;
- physical attacks against offices, equipment, or infrastructure;
- denial-of-service or distributed denial-of-service attacks;
- spam, excessive automated requests, or activities intended to degrade service availability;
- vulnerabilities that require physical access to a user's device or account;
- purely theoretical vulnerabilities without a practical security impact.
4. Rules of Testing
Security testing must be performed carefully and in a way that minimizes any risk to Taleino and its users.
4.1. User Data
Researchers must not:
- access personal information belonging to other users beyond what is strictly necessary to demonstrate a vulnerability;
- copy, download, publish, or retain user data;
- modify or delete another user's content;
- access another user's account without authorization;
- use discovered credentials or session information for purposes other than demonstrating the reported vulnerability.
If access to another user's data occurs unintentionally, the researcher should stop testing immediately and report the issue to Taleino without further accessing or copying the data.
4.2. Availability
Researchers must not:
- perform denial-of-service or distributed denial-of-service attacks;
- intentionally overload Taleino infrastructure;
- perform high-volume automated scanning;
- send large numbers of requests that could materially affect service performance.
4.3. Account and Authentication Testing
Researchers may test authentication and authorization mechanisms using accounts they control.
Researchers must not:
- attempt to take over accounts belonging to other users;
- use stolen credentials;
- conduct credential stuffing attacks against Taleino;
- attempt to bypass authentication in a way that could compromise other users.
4.4. Social Engineering and Physical Security
The following activities are not permitted:
- phishing;
- vishing;
- impersonation of Taleino employees or customers;
- attempts to obtain credentials from Taleino personnel;
- physical intrusion;
- attempts to access physical infrastructure or equipment.
4.5. General Restrictions
Researchers must not:
- install malware, backdoors, rootkits, or other malicious software;
- intentionally modify or destroy Taleino systems or data;
- attempt to compromise monitoring, logging, backup, or infrastructure management systems;
- sell or transfer access obtained through a vulnerability;
- use a vulnerability for financial gain;
- publicly disclose an unremediated vulnerability without first contacting Taleino.
5. What We Ask For
A useful vulnerability report should contain as much of the following information as reasonably possible.
5.1. Vulnerability Description
Please provide:
- vulnerability type, if known;
- affected URL, page, endpoint, or component;
- description of the vulnerability;
- explanation of how the vulnerability works;
- affected account type or permissions, if relevant;
- CVSS score, if available.
5.2. Steps to Reproduce
Please provide:
- clear reproduction steps;
- required account or permission level;
- relevant requests and responses;
- screenshots or screen recordings where useful;
- browser, operating system, or software version where relevant;
- proof of concept, where appropriate.
5.3. Security Impact
Please explain:
- what an attacker could potentially achieve;
- what data or functionality could be affected;
- whether other users could be affected;
- whether the issue could lead to unauthorized access, data disclosure, account takeover, or service disruption.
5.4. Suggested Remediation
If possible, include a recommendation for addressing the vulnerability.
This is optional but may help us investigate and resolve the issue more efficiently.
6. Response and Remediation
6.1. Taleino will make reasonable efforts to acknowledge valid security reports promptly.
Our target response times are:
| Stage | Target |
|---|---|
| Acknowledgment | Within 3 business days |
| Initial assessment | Within 10 business days |
| Status updates | As reasonably appropriate |
| Remediation | Based on severity, complexity, and available resources |
6.2. Response and remediation timelines are targets rather than contractual guarantees.
6.3. We may request additional information from the researcher during the investigation.
6.4. We may decline to provide detailed information about internal security measures, infrastructure, or remediation procedures where disclosure could create additional security risks.
6.5. Severity
We may use the following general severity classification:
| Severity | General Priority |
|---|---|
| Critical | Immediate or highest priority |
| High | High priority |
| Medium | Normal priority |
| Low | Lower priority |
Severity is determined based on the actual security impact, exploitability, affected systems, required privileges, and other relevant factors.
6.6. A vulnerability may be reclassified after further investigation.
6.7. After remediation, Taleino may notify the researcher that the issue has been addressed.
7. Rewards and Recognition
7.1. Taleino does not currently operate a paid bug bounty program.
7.2. Submission of a vulnerability report does not create an entitlement to financial compensation, free products, credits, or other rewards.
7.3. At our discretion, Taleino may recognize researchers who make significant responsible disclosures.
7.4. Taleino will not publicly identify a researcher without their permission.
7.5. If a researcher wishes to be credited publicly, they may indicate this in their report.
8. Good-Faith Security Research
8.1. Taleino appreciates security research conducted in accordance with this Policy.
8.2. Where a researcher:
- acts in good faith;
- follows this Policy;
- avoids unnecessary access to user data;
- avoids disruption of Taleino services;
- does not use a vulnerability for unauthorized gain; and
- reports the issue responsibly,
Taleino will take the researcher's good-faith conduct into account when evaluating the appropriate response to the reported activity.
8.3. This Policy does not grant permission to access systems beyond the scope described above and does not provide immunity from laws or regulations.
8.4. Researchers remain responsible for complying with applicable laws.
8.5. Taleino reserves the right to take appropriate action where testing involves malicious activity, intentional harm, unauthorized disclosure of personal information, financial exploitation, or material violation of this Policy.
9. Coordinated Disclosure
9.1. We ask researchers not to publicly disclose a vulnerability before Taleino has had a reasonable opportunity to investigate and remediate it.
9.2. If a researcher intends to publish information about a vulnerability, we ask that they contact Taleino in advance and provide reasonable time for remediation.
9.3. After remediation, Taleino may coordinate with the researcher regarding the timing and content of any public disclosure.
9.4. Taleino respects a researcher's choice to remain anonymous.
10. Third-Party Services
10.1. Taleino may use third-party providers for hosting, payments, authentication, email delivery, analytics, AI services, storage, or other infrastructure.
10.2. Vulnerabilities that exist exclusively within third-party systems should normally be reported directly to the relevant provider.
10.3. If a third-party vulnerability affects Taleino because of our implementation or configuration, we encourage researchers to report it to us as well.
10.4. Taleino may coordinate with the relevant third-party provider when necessary to investigate or resolve a security issue.
11. Contact Information
For security vulnerability reports:
Email: [email protected]
Suggested subject:
[Security Report] Brief description
For general inquiries:
Email: [email protected]
Website: https://taleino.com
Service Owner: FOP Gaitan Kyrylo Oleksandrovych
Registration Country: Ukraine
12. Policy Changes
Taleino may update this Security Disclosure Policy from time to time.
Changes may be made to reflect:
- changes to Taleino's services or infrastructure;
- changes in applicable law;
- changes in security practices;
- feedback from security researchers;
- changes to contact information or reporting procedures.
The current version of this Policy will be published on the Taleino website.
Last updated: September 12, 2026