Skip to content

Last updated: September 5, 2026

Vulnerability Disclosure Policy

PT BCB Academy Indonesia publishes Snipset and the services around it. This page explains how to report a security vulnerability to us and what you can expect from us in return.

COMMITMENT

Our Commitment

Security is a shared effort. We treat reports seriously and respond to them quickly.

PT BCB Academy Indonesia is committed to the security of the Snipset products and services and to protecting the people who use them. We welcome reports from security researchers and from anyone who discovers a potential vulnerability in our systems. We will work with you to understand the issue, confirm it, and resolve it as quickly as we responsibly can.

SCOPE

What Is In Scope

Only the systems and services we operate are covered by this policy.

This policy applies to the systems and services we operate, including:

  • the snipset.belajarcarabelajar.com website, blog, and documentation;
  • the Snipset web application;
  • the Snipset desktop application and its update service;
  • the Snipset Android application;
  • the public APIs and backend services that support the products above;
  • related services and endpoints we operate on the belajarcarabelajar.com domain.

Out of scope

  • third-party services and platforms we use, such as payment processors, hosting providers, and analytics. Please report issues with those services to the respective vendor;
  • physical security of offices or data centers;
  • social engineering, phishing, or denial-of-service (DoS/DDoS) attacks;
  • spam and content-related issues;
  • already-known issues, or vulnerabilities that require unrealistic user interaction.
HOW TO REPORT

How to Report a Vulnerability

Use the mailbox below. Reports go straight to our team.

Send your report to security@snipset.belajarcarabelajar.com. A member of our team monitors this mailbox and will triage what you send.

To help us handle your report quickly, please include:

  • a description of the vulnerability and its potential impact;
  • the URL, endpoint, product, or system affected;
  • step-by-step instructions to reproduce the issue;
  • a proof of concept, such as screenshots, requests, or scripts. Do not access, modify, or store data belonging to other users;
  • your name and contact information. You may remain anonymous if you prefer.

If the issue affects a public repository we maintain, you may also use the repository's private security reporting channel.

SAFE HARBOR

Safe Harbor

Good-faith research under this policy is authorized.

We consider security research that follows this policy to be authorized and in good faith. When you:

  • act in good faith and avoid privacy violations, data destruction, and service disruption;
  • test only against systems that are within scope;
  • do not access, modify, or store data belonging to other users. Use your own test accounts where possible;
  • stop testing and report immediately if you encounter sensitive user data;
  • give us reasonable time to fix the issue before any public disclosure;

PT BCB Academy Indonesia will not pursue legal action against you and will not refer you to enforcement authorities in connection with a report that follows these rules.

RESPONSE COMMITMENTS

Our Response Commitments

What you can expect after you submit a report.

StepTimeframe
We acknowledge receipt of your reportWithin 3 business days
We provide an initial assessment and severity ratingWithin 10 business days
We provide status updatesAt least every 14 days until resolution
Target resolutionWithin 90 days, depending on severity and complexity
RULES OF ENGAGEMENT

Rules of Engagement

Please test safely and respect other users while you do.

  • make every effort to avoid degrading the availability of our services;
  • never access, download, or modify data that does not belong to you;
  • stop testing and report immediately if you encounter sensitive user data;
  • do not run automated scans that generate significant traffic;
  • do not publicly disclose the vulnerability before we have resolved it and agreed on a disclosure date.
DISCLOSURE & RECOGNITION

Disclosure & Recognition

We coordinate public disclosure and can credit your work.

We ask that you give us a reasonable amount of time to remediate an issue before any public disclosure. We are happy to coordinate a shared disclosure timeline with you.

With your permission, we may acknowledge your contribution on this page in the Hall of Fame. We do not currently offer monetary rewards and do not operate a formal bug bounty program.

Hall of Fame entries will appear here when we publish an acknowledgment with the researcher's consent.

LEGAL

Governing Law

How this policy is administered.

This policy is governed by the laws of Indonesia. We may update this policy from time to time; the latest version will always be available at this URL.

If you have questions about this policy or about our security practices, email security@snipset.belajarcarabelajar.com.

Related reading: Security & Trust Center and Privacy Policy.