SPCY SPCY App

安全漏洞通報政策

最後更新日期:2026年8月11日

SPCY App 生態系統(下稱「本服務」、「我哋」)十分重視安全。本政策說明點樣向我哋回報安全漏洞、回報嘅範圍、我哋嘅回覆時間,以及對善意回報者嘅安全港承諾。本政策同 security.txt 檔案配套使用。

1. 回報範圍

喺範圍內:任何 SPCY App 網頁應用同共用平台嘅安全漏洞,包括 AI Studio、Drink Record(MT)、SmartSpend AI(Expense)、Score Editor、Mindmap PPT / AI Slides、Transcribe、Notebook,以及共用嘅登入(Auth)、點數與付費(Billing)同 API(spcy.hk)。

唔喺範圍內:

  • 第三方服務嘅漏洞(Google、Stripe、Cloudflare、各 AI 供應商等)——請直接向佢哋回報。
  • 拒絕服務(DoS / DDoS)或令服務降級嘅攻擊。
  • 社交工程、釣魚或針對我哋員工 / 用戶嘅物理攻擊。
  • 只影響你自己帳號嘅自我 XSS 或 CSRF。
  • 已經過時嘅瀏覽器或第三方插件嘅漏洞。
  • 點列出可枚舉嘅資訊(例如版本號、用戶 ID 存在與否)而冇實際安全影響嘅情況。

2. 點樣回報

請用電郵回報至 [email protected]。回報之前請先聯絡我哋,唔好公開披露。

為咗令我哋可以快速處理,請盡量提供以下資訊:

  • 受影響嘅應用同確實 URL / 端點。
  • 重現步驟(越詳細越好,最好附上概念驗證)。
  • 漏洞嘅影響,同攻擊者可以做到咩。
  • 你嘅聯絡資料,以及你想唔想喺致謝名單留名。

收到我哋確認同修復之後,歡迎你公開披露。

3. 回覆時間

本服務由單人創辦者營運,所以時間係盡力而為,但我哋會保持溝通:

  • 72 小時內確認收到你嘅回報。
  • 7 日內完成初步評估同分級。
  • 嚴重漏洞目標 14 日內修復;其他級別按實際情況盡快處理。
  • 如果修復需時較長,我哋會話俾你知進度同預計時間。

4. 安全港(善意回報)

對於善意而且遵守本政策嘅回報,我哋承諾:

  • 唔會就回報本身向你採取法律行動。
  • 將你對該漏洞嘅測試視為經授權嘅行為。
  • 與你合作,喺合適嘅時間協調披露。

作為回報者,你必須:

  • 避免存取或修改其他人嘅資料;如果你意外存取到,請立即刪除並話俾我哋知。
  • 唔好令服務降級或影響其他用戶。
  • 一旦展示到個問題就停止測試。
  • 喺我哋有合理時間修復之前,唔好公開披露。

違反以上任何一點嘅回報唔受安全港保障。

5. 致謝與獎勵

本服務目前未有正式嘅漏洞懸賞計劃(Bug Bounty),亦未產生收入。但凡係有效嘅回報,我哋會喺你嘅同意之下喺致謝名單留名;如果你想匿名,我哋亦會尊重。呢個政策可能會喺將來更新。

6. 法律說明

本政策唔構成合約,亦唔賦予除「安全港」以外嘅任何權利。本政策以英文版本為準;如各語言版本有任何差異,以英文版本為準。本政策嘅最終解釋權歸本服務所有。

如有任何問題,請透過 [email protected] 聯繫開發團隊。

© 2026 SPCY App Ecosystem. 本文件受版權保護。

Security Vulnerability Disclosure Policy

Last updated: 11 August 2026

The SPCY App ecosystem (the "Service", "we") takes security seriously. This policy explains how to report security vulnerabilities to us, what is in scope, our response timelines, and our safe-harbor commitment to good-faith reporters. It accompanies the machine-readable security.txt file.

1. Scope

In scope: security vulnerabilities in any SPCY App web application or the shared platform — AI Studio, Drink Record (MT), SmartSpend AI (Expense), Score Editor, Mindmap PPT / AI Slides, Transcribe, Notebook, and the shared Auth, Credits & Billing, and API (spcy.hk).

Out of scope:

  • Vulnerabilities in third-party services (Google, Stripe, Cloudflare, AI providers, etc.) — report these to the service operator directly.
  • Denial-of-service (DoS / DDoS) or attacks that degrade service availability.
  • Social engineering, phishing, or physical attacks against our staff or users.
  • Self-XSS or CSRF that only affects your own account.
  • Vulnerabilities in outdated browsers or third-party browser extensions.
  • Enumerable information (version banners, user-id existence) with no real security impact.

2. How to report

Email your report to [email protected]. Please contact us before any public disclosure.

To help us triage quickly, please include as much of the following as possible:

  • The affected application and the exact URL / endpoint.
  • Steps to reproduce (detailed, ideally with a proof of concept).
  • The impact of the vulnerability and what an attacker could do.
  • Your contact details, and whether you would like to be credited.

Once we have confirmed and remediated the issue, you are welcome to disclose it publicly.

3. Response timeline

This Service is run by a solo founder, so timelines are best-effort, but we will keep you informed:

  • Acknowledge receipt within 72 hours.
  • Initial assessment and triage within 7 days.
  • Critical vulnerabilities targeted for fix within 14 days; others handled as soon as practical.
  • If a fix will take longer, we will keep you updated on progress and an estimated timeline.

4. Safe harbor (good-faith reporting)

For good-faith reports that follow this policy, we commit to:

  • Not taking legal action against you for the report itself.
  • Treating your testing of the reported vulnerability as authorized.
  • Working with you to coordinate disclosure at a suitable time.

In return, you must:

  • Avoid accessing or modifying other people's data; if you accidentally do, delete it immediately and tell us.
  • Not degrade the service or affect other users.
  • Stop testing once you have demonstrated the issue.
  • Not disclose the vulnerability publicly until we have had a reasonable time to fix it.

Reports that breach any of the above are not covered by safe harbor.

5. Recognition & rewards

This Service does not currently run a formal bug-bounty program and is pre-revenue. For valid reports we are happy to credit you in an acknowledgments section with your consent, or keep you anonymous if you prefer. This policy may be updated in the future.

6. Legal notes

This policy is not a contract and grants no rights beyond safe harbor for good-faith reports. The English version is the controlling version; in the event of any discrepancy between language versions, the English version prevails. We reserve the right to interpret this policy in good faith.

For any questions, contact the development team at [email protected].

© 2026 SPCY App Ecosystem. This document is protected by copyright.