At Homzo Hospitality, security is not an afterthought — it is a foundational pillar of everything we build. We process sensitive guest information, hotel partner data, and financial transactions daily, and we take the responsibility of protecting that data with the utmost seriousness.
We value the independent security research community and recognize the vital role researchers play in keeping digital platforms safe. This policy outlines how you can responsibly disclose potential vulnerabilities to us, and how we commit to working with you in good faith.
Proactive defense of all our digital assets and infrastructure.
Safeguarding guest and customer personal data at every touchpoint.
Ensuring hotel and business partners can trust our platform.
A clear, ethical process for disclosing vulnerabilities.
If you believe you have discovered a security vulnerability in any Homzo Hospitality website, mobile application, API, or system, please reach out to our security team immediately. We ask that you follow responsible disclosure principles and contact us privately before any public disclosure.
Please use email to submit all vulnerability reports. Do not share details on public forums before we have had the opportunity to investigate.
When you report a vulnerability to us in good faith, Homzo Hospitality is committed to working with you transparently and professionally throughout the resolution process.
We will acknowledge receipt of your report within 72 hours, confirming we have received it and are reviewing the details.
Our security team will conduct a thorough investigation to verify and assess the severity of the reported vulnerability.
We will work diligently to remediate confirmed vulnerabilities in a timely manner, prioritized by impact and severity.
We will keep you informed of our progress and notify you when the vulnerability has been resolved.
To ensure a productive and ethical research process, we ask that all security researchers adhere to the following guidelines when investigating potential vulnerabilities in Homzo Hospitality systems.
The following types of issues are outside the scope of this responsible disclosure policy. Reports in these categories will not be considered for acknowledgment or response.
We believe that good-faith security research should be encouraged, not punished. Homzo Hospitality is committed to protecting researchers who act responsibly and within the bounds of this policy.
Homzo Hospitality will not pursue civil or criminal action against security researchers who discover and report vulnerabilities in compliance with this Responsible Disclosure Policy. We consider responsible disclosure activities to be authorized, constructive conduct and will work with our legal team to ensure researchers are protected when they operate in good faith.
Have a security concern, question about this policy, or a vulnerability to report? Our security team is ready to assist you.
support@homzohospitality.com