Vulnerability Disclosure Policy

Last updated September 25, 2026

Vivid Productions, LLC, doing business as MobileTopup.com, values the work of independent security researchers in keeping our users safe. This page explains how to report a suspected security vulnerability in our systems and what to expect from us in response.

Scope

The following are in scope for vulnerability reports:

  • mobiletopup.com (the main website and web app)
  • The admin panel at mobiletopup.com/admin — report-only; please do not attempt to log in or actively test this panel
  • partners.mobiletopup.com, including the Partner API v1
  • agent.mobiletopup.com (the Eve AI agent)
  • Our iOS and Android mobile applications

Out of scope: dev.mobiletopup.com and any other staging/development subdomain are explicitly out of scope — they run against live production data and must not be targeted. Also out of scope: denial-of-service testing, spam or social engineering against our staff or users, physical security testing, and automated vulnerability scanning that generates significant traffic without prior coordination with us.

How to Report

Please email [email protected] with one issue per email. To help us triage and reproduce your report quickly, please include:

  • A description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions or a proof of concept
  • The URL, endpoint, or app version affected
  • Any tools or scripts used, so we can distinguish your testing traffic from an attack

Please do not include real customer data, payment card numbers, or account passwords in your report.

Our Response

We will acknowledge receipt of your report within 3 business days. We will keep you informed of our progress as we investigate and remediate confirmed issues, and we will let you know once a fix has been deployed.

Safe Harbor

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: testing only in-scope systems, avoiding harm to our users and services, not accessing or exfiltrating more data than necessary to demonstrate an issue, and reporting findings to us promptly and privately before any public disclosure.

Recognition

We do not currently offer a paid bug bounty program. We are happy to credit researchers who report valid, previously-unknown vulnerabilities, with their permission, once a fix has shipped.

Contact

Email [email protected]. A machine-readable copy of this contact information is published at /.well-known/security.txt per RFC 9116.