Branch International | Responsible Disclosure Policy

Responsible Disclosure Policy

Branch International Responsible Disclosure Policy

We take the security of our systems seriously, and we value the security community. The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our users.

Guidelines

We require that all researchers:

If you follow these guidelines when reporting an issue to us, we commit to:

Scope

In-scope Systems
Out-of-scope Systems

In the interest of the safety of our users, staff and you as a security researcher, the following test types are excluded from scope:

Things we do not want to receive:

Reporting a Security Vulnerability

If you believe you’ve found a security vulnerability in one of our products or platforms please send it to us by emailing disclosure@branch.co. Please include the following details with your report: