Security

Vulnerability Disclosure Policy

Effective Date: January 1, 2026

Padi welcomes responsible security research and encourages the reporting of potential vulnerabilities. This Policy outlines how security issues should be reported and how we handle disclosed vulnerabilities.

01

Purpose

Padi is committed to maintaining the security and integrity of our products, services, systems, and user data. This Vulnerability Disclosure Policy provides guidance for security researchers, customers, and members of the public who wish to report potential security vulnerabilities to us.

02

Scope

This Policy applies to vulnerabilities identified within Padi-owned websites, applications, APIs, infrastructure, and services that are actively maintained and publicly accessible. Third-party services and systems outside our control are not covered by this Policy.

03

Responsible Disclosure

We encourage responsible disclosure of security vulnerabilities. Researchers should provide us with reasonable time to investigate and remediate reported issues before publicly disclosing any findings.

04

How to Report a Vulnerability

If you discover a security vulnerability, please provide a detailed report including a description of the issue, affected systems or URLs, reproduction steps, proof-of-concept information where applicable, potential impact, and your contact information.

05

Reporting Channel

Security vulnerabilities should be reported by email to [email protected]. Reports should contain sufficient detail to allow our team to understand, validate, and reproduce the issue.

06

What We Expect

When conducting security research, we ask that you act in good faith, avoid privacy violations, avoid service disruption, avoid accessing data belonging to other users, and refrain from exploiting vulnerabilities beyond what is reasonably necessary to demonstrate their existence.

07

Prohibited Activities

Researchers must not access, modify, destroy, download, disclose, or retain customer data. Denial-of-service attacks, spam, phishing, social engineering, physical attacks, ransomware deployment, malware testing, and attempts to gain persistent access are strictly prohibited.

08

Our Commitment

Upon receiving a valid vulnerability report, we will acknowledge receipt, investigate the issue, assess severity and impact, and take appropriate remediation measures. We aim to maintain clear communication throughout the process where possible.

09

Safe Harbour

Padi will not pursue legal action against individuals who discover and report vulnerabilities in good faith and in accordance with this Policy. Activities that exceed the scope of this Policy or violate applicable laws are not covered by this safe harbour commitment.

10

Confidentiality

Information relating to reported vulnerabilities should be treated as confidential until remediation has been completed and public disclosure has been agreed upon by all parties.

11

Recognition

While Padi does not currently operate a bug bounty programme, we appreciate responsible disclosures that help improve the security of our platform. We may choose to acknowledge contributions at our discretion.

12

Policy Updates

This Policy may be updated periodically to reflect changes in our security practices, reporting procedures, technologies, or legal obligations. Updated versions will be published on this page.

13

Contact Information

Questions regarding this Vulnerability Disclosure Policy may be directed to [email protected].