Vulnerability Disclosure Policy
FitPDF welcomes good-faith reports of security vulnerabilities affecting the FitPDF website or application. We value responsible disclosure and will assess credible reports in a timely manner.
Reporting a concern
Please submit reports to hello@lunaruplink.com. To help us assess a report, include a clear description of the issue, its potential effect, and sufficient information to reproduce it. Do not include personal, confidential, or production documents; use synthetic material wherever possible.
Our process
FitPDF will acknowledge a qualifying report within 5 business days and will provide an initial assessment within 10 business days. We may request additional information, provide status updates where appropriate, and recognize a reporter in release communications with the reporter's consent.
Scope
This policy applies to the FitPDF website and application at https://fitpdf.ca. Reports concerning unauthorized disclosure, unauthorized access, integrity failures, or material security weaknesses in FitPDF are within scope.
The following are ordinarily outside scope: service-disruption testing, social engineering, physical attacks, automated findings without a demonstrated impact, and vulnerabilities in services operated by third parties. Such reports should be directed to the applicable provider.
Good-faith research
FitPDF will not pursue legal action against a researcher who follows this policy in good faith. Good-faith research must avoid privacy violations, data loss, and service disruption; must use only data the researcher is authorized to test; and must allow FitPDF a reasonable opportunity to address the issue before public disclosure.