Skip to main content
Loyca

Security

Responsible disclosure

Reporting an issue

If you have found a security issue in a system Loyca operates, tell us at loycaofficial@gmail.com. Include enough detail to reproduce it: the URL or endpoint, the steps, and what you observed. A proof of concept helps.

What we commit to

  • We acknowledge reports and tell you whether we can reproduce the issue.
  • We keep you informed while we fix it.
  • We credit you if you want credit, and stay quiet about you if you do not.
  • We do not pursue legal action against researchers acting in good faith under this policy.

We do not run a paid bug bounty, so we cannot promise a reward. We would rather say that plainly than imply otherwise.

In scope

  • This website and its subdomains
  • Systems Loyca operates and identifies as ours

Out of scope

  • Our clients’ systems. We cannot authorise testing of assets we do not own. Report those to the owner.
  • Third-party services we merely use, such as our hosting provider
  • Denial of service, volumetric or resource-exhaustion testing
  • Social engineering of Loyca staff, and physical attacks
  • Findings from an automated scanner with no demonstrated impact
  • Missing headers or best-practice notes with no exploitable consequence

Ground rules

Stay within scope. Do not access, modify or exfiltrate data that is not yours — if you reach someone’s personal data, stop and tell us. Do not degrade service for others. Give us reasonable time to fix an issue before publishing.

Reading this because you are assessing us

Fair. A firm that sells security assessment should be able to take a report. Ask us anything.

Message Loyca on WhatsApp