🛡️

Security at the Heart of Hospitality

At Homzo Hospitality, security is not an afterthought — it is a foundational pillar of everything we build. We process sensitive guest information, hotel partner data, and financial transactions daily, and we take the responsibility of protecting that data with the utmost seriousness.

We value the independent security research community and recognize the vital role researchers play in keeping digital platforms safe. This policy outlines how you can responsibly disclose potential vulnerabilities to us, and how we commit to working with you in good faith.

Cybersecurity

Proactive defense of all our digital assets and infrastructure.

User Privacy

Safeguarding guest and customer personal data at every touchpoint.

Partner Security

Ensuring hotel and business partners can trust our platform.

Responsible Reporting

A clear, ethical process for disclosing vulnerabilities.

📋

How to Report a Vulnerability

If you believe you have discovered a security vulnerability in any Homzo Hospitality website, mobile application, API, or system, please reach out to our security team immediately. We ask that you follow responsible disclosure principles and contact us privately before any public disclosure.

Contact Details

Please use email to submit all vulnerability reports. Do not share details on public forums before we have had the opportunity to investigate.

Please include in your report:

  • A clear description and affected component
  • Step-by-step reproduction instructions
  • Screenshots, videos, or PoC code
  • Potential impact and severity estimate
  • Your name and preferred contact details
🤝

Our Commitment to Researchers

When you report a vulnerability to us in good faith, Homzo Hospitality is committed to working with you transparently and professionally throughout the resolution process.

01

Acknowledgment

We will acknowledge receipt of your report within 72 hours, confirming we have received it and are reviewing the details.

02

Investigation

Our security team will conduct a thorough investigation to verify and assess the severity of the reported vulnerability.

03

Remediation

We will work diligently to remediate confirmed vulnerabilities in a timely manner, prioritized by impact and severity.

04

Communication

We will keep you informed of our progress and notify you when the vulnerability has been resolved.

📜

What We Ask of Researchers

To ensure a productive and ethical research process, we ask that all security researchers adhere to the following guidelines when investigating potential vulnerabilities in Homzo Hospitality systems.

Act in Good Faith Conduct testing ethically and with genuine intent to improve our platform's security.
No Data Access or Modification Do not access, modify, copy, or delete any user or system data beyond what is strictly necessary to demonstrate the vulnerability.
No Service Disruption Avoid any actions that could degrade, disrupt, or deny access to Homzo Hospitality services for other users.
No Privacy Violations Do not access, expose, or exploit personal data belonging to real users, guests, or hotel partners.
Allow Reasonable Time to Remediate Please allow us a reasonable timeframe (up to 90 days) to investigate and remediate before any public disclosure.
Only Test Your Own Accounts Use accounts and data that you own or have explicit permission to test. Never test on accounts belonging to other users.
🚫

Vulnerabilities Outside Our Scope

The following types of issues are outside the scope of this responsible disclosure policy. Reports in these categories will not be considered for acknowledgment or response.

DDoS Attacks Distributed denial-of-service attacks or any testing involving network flooding or resource exhaustion.
Spam Attacks Email bombing, SMS flooding, or any form of mass unsolicited messaging targeting our systems or users.
Social Engineering Phishing, vishing, pretexting, or any form of social engineering targeting Homzo employees or contractors.
Physical Security Issues Physical intrusion, tailgating, or any security concern related to Homzo's or partner hotels' physical premises.
Non-Exploitable Findings Theoretical vulnerabilities, informational issues, or findings without a demonstrable real-world security impact.
Third-Party Services Vulnerabilities in third-party platforms or services that are not under Homzo Hospitality's direct control or responsibility.
⚖️

Legal Safe Harbor

We believe that good-faith security research should be encouraged, not punished. Homzo Hospitality is committed to protecting researchers who act responsibly and within the bounds of this policy.

Our Safe Harbor Commitment

Homzo Hospitality will not pursue civil or criminal action against security researchers who discover and report vulnerabilities in compliance with this Responsible Disclosure Policy. We consider responsible disclosure activities to be authorized, constructive conduct and will work with our legal team to ensure researchers are protected when they operate in good faith.

  • No legal action against researchers who act in good faith and follow this policy.
  • We will not report you to law enforcement for responsible disclosures.
  • We view your research as authorized under this policy when guidelines are followed.
  • We may publicly acknowledge your responsible disclosure with your consent.
📞

Security Contact & Support

Have a security concern, question about this policy, or a vulnerability to report? Our security team is ready to assist you.

support@homzohospitality.com