Responsible Vulnerability Disclosure Policy

DaySmart welcomes contributions from the security research community. If you believe you've found a security vulnerability in any DaySmart product or service, we encourage you to report it responsibly.

Last updated: April 17, 2026

Scope

The following assets are currently covered under this program. The maximum severity column indicates the highest severity rating we will accept for each asset.

ProductAsset IdentifierMax Severity
Boxmateadmin.boxmateapp.co.ukCritical
Dashapps.daysmartrecreation.comCritical
DaySmart Appointmentsaccount.appointment-plus.comCritical
DaySmart Body Artcloud.daysmartbodyart.comCritical
DaySmart Passportlogin.daysmart.comCritical
DaySmart Payrollpayroll.daysmart.comCritical
DaySmart Petcloud.daysmartpet.comCritical
DaySmart Saloncloud.daysmartsalon.comCritical
DaySmart Spacloud.daysmartspa.comCritical
DaySmart Vetvettersoftware.comCritical
Sawyer (Business)hisawyer.com/for-businessCritical
Sawyer Marketplacehisawyer.com/exploreCritical
Slicksalon.getslick.comCritical
TeamUpgoteamup.comCritical
TimeToPetwww.timetopet.comCritical

Assets not listed above are not yet covered under this program. If you'd like to inquire about a specific asset, please contact us and we'll update this table accordingly — including noting any assets that are ineligible or have a reduced maximum severity.

Rules of Engagement

When researching vulnerabilities, you must:

  • Only test against accounts you own or have explicit authorization to test
  • Not access, modify, or delete data belonging to other users
  • Not perform actions that could degrade service availability (e.g., denial of service, brute force attacks, resource exhaustion)
  • Not use automated scanning tools against production systems without prior approval
  • Not perform physical security attacks or social engineering against DaySmart employees
  • Stop testing and report immediately if you access any user data beyond your own

How to Report

Submit vulnerability reports through our submission portal or email security@daysmart.com. Please include:

  • A detailed description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • The affected URL(s), parameters, or endpoints
  • Proof-of-concept code, screenshots, or video if applicable
  • Your suggested severity assessment (Critical, High, Medium, Low)

What to Expect

  1. Acknowledgment — We will acknowledge receipt of your report within 3 business days.
  2. Triage — Our security team will assess the severity and validity within 10 business days.
  3. Resolution — We will work to remediate confirmed vulnerabilities in a timeframe appropriate to their severity.
  4. Disclosure — We will coordinate with you on public disclosure timing after the fix is deployed.

Safe Harbor

DaySmart considers security research conducted in accordance with this policy to be authorized conduct. We will not pursue legal action against researchers who:

  • Act in good faith and follow this policy
  • Avoid privacy violations, data destruction, and service disruption
  • Report vulnerabilities promptly and do not publicly disclose them before remediation
  • Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue

If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will make it known that your actions were authorized under our program.

Out of Scope

The following issue types are generally not eligible:

  • Clickjacking on pages with no sensitive actions
  • Missing security headers that do not lead to a direct exploit
  • Missing email best practices (SPF/DKIM/DMARC) without demonstrated impact
  • Software version disclosure without a proven vulnerability
  • Vulnerabilities only affecting outdated browsers or platforms
  • Rate limiting or brute force issues on non-authentication endpoints
  • Content spoofing or text injection without demonstrated impact

Ready to submit a report?

Report a Vulnerability

or email security@daysmart.com