Web and Cloud Innovation Ltd ("we") runs a service that holds other people's papers. If you find a way in that we did not intend, we would rather hear it from you than from anybody else, and this page says how.
1What We Ask Of You
Tell us privately, at legal@premises.ph, before you tell anyone else. Give us enough to reproduce what you found: the address, the steps, and what you saw. If you can, include the date and time so we can find it in our own log.
Do not go further than you need to in order to show the weakness exists. Do not read, copy, change or delete data that is not yours. Do not run denial-of-service tests, social engineering, or anything physical. Do not use the demonstration to attack anything other than the demonstration.
2What We Promise In Return
We will acknowledge your report within three working days and tell you what we intend to do within ten. We will keep you informed while we fix it and tell you when it is fixed. We will not take legal action against anybody who follows the rules above in good faith. If you want to be named when the fix is published, we will name you; if you do not, we will not.
3What Is In Scope
The public website at premises.ph, the application at any address ending in .premises.ph, and the demonstration at demo.premises.ph.
Out of scope: our hosting provider's own infrastructure, our registrar, our email provider, and anything that is not ours to fix. Reports about missing security headers on pages that hold no data, version disclosure, or "best practice" items with no demonstrated impact are welcome but are not treated as urgent.
4What Happens If Someone Else's Data Is Involved
If your report shows that a business's data could have been reached by somebody who should not have reached it, we treat that as an incident under our Data Processing Agreement: the business is told within seventy-two hours of our confirming it, and the National Privacy Commission is notified where the law requires.