Responsible Vulnerability Disclosure Policy
DaySmart welcomes contributions from the security research community. If you believe you've found a security vulnerability in any DaySmart product or service, we encourage you to report it responsibly.
Last updated: April 17, 2026
Scope
The following assets are currently covered under this program. The maximum severity column indicates the highest severity rating we will accept for each asset.
| Product | Asset Identifier | Max Severity |
|---|---|---|
| Boxmate | admin.boxmateapp.co.uk | Critical |
| Dash | apps.daysmartrecreation.com | Critical |
| DaySmart Appointments | account.appointment-plus.com | Critical |
| DaySmart Body Art | cloud.daysmartbodyart.com | Critical |
| DaySmart Passport | login.daysmart.com | Critical |
| DaySmart Payroll | payroll.daysmart.com | Critical |
| DaySmart Pet | cloud.daysmartpet.com | Critical |
| DaySmart Salon | cloud.daysmartsalon.com | Critical |
| DaySmart Spa | cloud.daysmartspa.com | Critical |
| DaySmart Vet | vettersoftware.com | Critical |
| Sawyer (Business) | hisawyer.com/for-business | Critical |
| Sawyer Marketplace | hisawyer.com/explore | Critical |
| Slick | salon.getslick.com | Critical |
| TeamUp | goteamup.com | Critical |
| TimeToPet | www.timetopet.com | Critical |
Assets not listed above are not yet covered under this program. If you'd like to inquire about a specific asset, please contact us and we'll update this table accordingly — including noting any assets that are ineligible or have a reduced maximum severity.
Rules of Engagement
When researching vulnerabilities, you must:
- Only test against accounts you own or have explicit authorization to test
- Not access, modify, or delete data belonging to other users
- Not perform actions that could degrade service availability (e.g., denial of service, brute force attacks, resource exhaustion)
- Not use automated scanning tools against production systems without prior approval
- Not perform physical security attacks or social engineering against DaySmart employees
- Stop testing and report immediately if you access any user data beyond your own
How to Report
Submit vulnerability reports through our submission portal or email security@daysmart.com. Please include:
- A detailed description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The affected URL(s), parameters, or endpoints
- Proof-of-concept code, screenshots, or video if applicable
- Your suggested severity assessment (Critical, High, Medium, Low)
What to Expect
- Acknowledgment — We will acknowledge receipt of your report within 3 business days.
- Triage — Our security team will assess the severity and validity within 10 business days.
- Resolution — We will work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity.
- Disclosure — We will coordinate with you on public disclosure timing after the fix is deployed.
Safe Harbor
DaySmart considers security research conducted in accordance with this policy to be authorized conduct. We will not pursue legal action against researchers who:
- Act in good faith and follow this policy
- Avoid privacy violations, data destruction, and service disruption
- Report vulnerabilities promptly and do not publicly disclose them before remediation
- Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will make it known that your actions were authorized under our program.
Out of Scope
The following issue types are generally not eligible:
- Clickjacking on pages with no sensitive actions
- Missing security headers that do not lead to a direct exploit
- Missing email best practices (SPF/DKIM/DMARC) without demonstrated impact
- Software version disclosure without a proven vulnerability
- Vulnerabilities only affecting outdated browsers or platforms
- Rate limiting or brute force issues on non-authentication endpoints
- Content spoofing or text injection without demonstrated impact