Legal
Vulnerability Disclosure Policy
If you have found a security problem in Ofivio: how to report it, what we promise in return, and the safe harbour that protects your research.
Last updated 9 September 2026
OFIVIO (SMC-PRIVATE) LIMITED · Lahore, Pakistan
1. If you have found something, we want to hear it
This document is a draft under review. It is published so customers can see the position we are working to, and it is being reviewed by our advisers before it becomes final. Where it conflicts with the Terms of Service, the Terms govern.
Report it to contact@ofivio.com with the subject line Security. Tell us what you found, where, and how to reproduce it. A short proof of concept is worth more than a scanner report.
2. Safe harbour
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat it as authorised access for the purposes of our own Acceptable Use Policy.
That protection ends if you take another customer's data, degrade the service for other people, or use what you find for anything other than telling us about it.
3. What we ask
- Use your own account and your own test workspace.
- Stop as soon as you have proved a problem exists. Do not read, change, or keep another customer's data — one record is enough to demonstrate access, and you should not take even that if a screenshot of the response header would do.
- No denial of service, no load testing, no spam, no social engineering of our staff or customers.
- Give us reasonable time to fix it before telling anyone else.
4. What we will do
- Acknowledge your report.
- Tell you whether we can reproduce it, and what we judge its severity to be.
- Keep you informed while we fix it, and tell you when it is fixed.
- Credit you publicly if you want that, and stay quiet about you if you do not.
5. There is no bug bounty
We do not currently pay for reports. We would rather say that plainly than let a researcher spend a weekend expecting one. If that changes it will be announced here.
6. Out of scope
- Findings from automated scanners with no demonstrated impact.
- Missing hardening headers with no exploitable consequence.
- Weaknesses in third-party services we consume — report those to their owners.
- Anything requiring physical access to a person's unlocked device.


