Vulnerability Disclosure Policy
Last updated: 22 September 2026
If you believe you have found a security vulnerability in YetOnePro, send a report to business@yetone.pro. English is preferred.
Testing boundaries
You may test YetOnePro using only accounts you own and data you control, subject to the rules below. This permission does not extend to other users’ accounts or data, or to third-party services.
- Do not perform denial-of-service (DoS or DDoS) attacks or tests that disrupt availability.
- Do not use social engineering, phishing, or impersonation of staff or users.
- Do not perform destructive testing or delete, corrupt, or modify other users’ data.
- Do not send spam, mass messages, or repeated email or notification requests.
- Do not access, download, or retain other users’ private data.
If you unexpectedly encounter another user’s data, stop testing immediately and report the issue. Do not investigate further or include that private data in your report.
What to include in your report
Email business@yetone.pro with a clear summary and:
- The affected URL, endpoint, or feature.
- Steps to reproduce using your own accounts and test data, including any prerequisites.
- The expected behavior, observed behavior, and practical security impact.
- A minimal proof of concept, or relevant requests, responses, and screenshots with sensitive values redacted.
- A way to contact you with follow-up questions.
Do not send passwords, access tokens, or other users’ personal information. Please report findings privately and coordinate public disclosure with us so that we can investigate and address the issue.
Bug bounty and rewards
YetOnePro does not currently operate a bug bounty program. Submission of a vulnerability report does not create an entitlement to financial compensation. Any reward, if offered, is entirely at YetOnePro's discretion.
Machine-readable contact information: security.txt.




