Handshakes Vulnerability Disclosure Programme

Last revised: 24 August 2026

ABOUT THIS PROGRAMME
Handshakes welcomes the responsible reporting of suspected security vulnerabilities in the systems listed below. This policy sets out what to report, how to report it, and what we will and will not do in response.

This policy does not authorise you to test, scan, probe, or attempt to exploit any Handshakes system. It is an invitation to report what you have found — not permission to go looking. Nothing in this policy authorises or permits any action that may contravene applicable law, including the Computer Misuse Act 1993 and the Personal Data Protection Act 2012. If you are in any doubt, seek your own legal advice before acting.

THIS IS NOT A BUG BOUNTY PROGRAMME

Handshakes does not pay for vulnerability reports. There is no bounty, reward, fee, gift, credit, or consideration of any kind — for any finding, at any severity, from any reporter. We do not negotiate on this point and we do not respond to correspondence about it. Invoices and payment requests will not be paid.

A submission that withholds detail pending payment, or that attaches a deadline backed by a threat to publish or to contact our customers, regulators, or the media, is not a security report. We record such submissions as a security incident, escalate them to our legal counsel, and may refer them to the Singapore Police Force.

SCOPE

CategoryAssets
In scopewww.handshakes.ai
app.handshakes.ai
public Handshakes APIs
Out of scopeEverything else — any other Handshakes host or subdomain, non-production environments, systems operated by our cloud, hosting or CDN providers, third-party services we consume but do not operate, our customers’ systems, and employee personal accounts and devices. Report third-party issues to the relevant vendor.

FINDINGS WE DO NOT ACCEPT

We do not triage findings we assess as informational. This includes configuration observations without demonstrated exploitation, issues of low or theoretical impact, unmodified output of automated scanning tools, and publicly known CVEs in third-party components reported without a working exploit against our systems. Such reports are closed without further correspondence, and our assessment is final.

Reports must demonstrate concrete impact to Handshakes or its customers. If you cannot show what an attacker gains, we will not be able to act on it.“Ar indirectly.

PROHIBITED ACTIVITY

The following are prohibited outright, not merely out of scope. Engaging in them voids any assurance given in this policy:

  • Denial of service, resource exhaustion, and any load or volumetric testing.
  • Social engineering, phishing, vishing, or smishing directed at Handshakes staff, customers, or suppliers.
  • Physical intrusion or any attack on Handshakes premises or personnel.

Handshakes credentials found in third-party breach corpora or infostealer logs are welcome at the address below, but are not vulnerability reports under this policy.

CODE OF CONDUCT

When reporting, you must:

  1. Act in good faith, for the sole purpose of improving security.
  2. Avoid cauvsing damage, harm, loss, interruption, or degradation of any kind. Do not attempt to reproduce or verify a suspected vulnerability at our expense.
  3. Stop immediately on encountering personal data, credentials, or customer content. Do not download, copy, retain, or disclose it. Tell us what you saw — in description, not in copies.
  4. Not access, create, modify, delete or exfiltrate any data or programme, install any backdoor or persistence, or alter any system configuration.
  5. Not disclose the issue publicly or to any third party without our prior written consent.
  6. Communicate professionally. Abusive or coercive correspondence ends our engagement with you.

WHAT TO INCLUDE IN YOUR REPORT

Send reports in English to security@handshakes.ai. Please include the affected host or URL; a description of the suspected vulnerability; the steps and circumstances that led to your discovery, with dates and times; why you believe it is exploitable and what the impact would be; and your contact details. Do not send us customer data, employee data, or any personal data as evidence. Do not send executables, archives, or macro-enabled documents — they are quarantined and will not be opened.

WHAT HANDSHAKES WILL DO

  1. Acknowledge receipt of your report automatically, on submission.
  2. Reach a triage decision within 10 business days of receipt, and notify you of the outcome once.
  3. Prioritise and remediate validated findings in accordance with our internal risk management process.
  4. Notify you when a validated finding is resolved, if you have asked to be told.
  5. Where you have complied with this policy, not initiate civil proceedings against you and not refer your activity to law enforcement.
  6. Keep your identity confidential, unless disclosure is required by law, regulation, or court order.
  7. On request and at our sole discretion, accord you recognition for a validated finding once it has been remediated.

WHAT HANDSHAKES WILL NOT DO

  1. Provide any cash reward or financial incentive of any kind.
  2. Accord or provide any exemption, immunity, indemnity, or shield from civil or criminal liability under applicable law. Only the Public Prosecutor may decline to prosecute under the Computer Misuse Act 1993.
  3. Bind any third party. This policy is given by DC Frontiers Pte Ltd on its own behalf, and does not bind our customers, our cloud, hosting or CDN providers, or any other party.
  4. Provide status updates on a fixed cadence, share internal ticket references, severity scores, remediation plans, or patch timelines.
  5. Enter into severity disputes. Validated findings are scored using CVSS v3.1 adjusted for our environment; our determination is final and not subject to appeal.
  6. Treat a later report of an issue already known to us as anything other than a duplicate.
  7. Accept responsibility for the contents of any report, or be obliged to consult you before any public statement about the issue.
  8. Extend any of the above to submissions that seek payment or make threats.

PERSONAL DATA

Handshakes is subject to the Personal Data Protection Act 2012. Unauthorised access to personal data we hold may be a notifiable data breach regardless of intent. If your activity results in such access, tell us immediately, delete all copies, and confirm deletion in writing when we ask. Personal data you provide in your report is processed to manage the report and retained as part of our security records.

CONTACT

ChannelDetail
Emailsecurity@handshakes.ai
Machine-readablehttps://www.handshakes.ai/.well-known/security.txt

This policy is governed by the laws of the Republic of Singapore. We may amend it at any time; the version published when you submit is the version that applies. Participation is voluntary and creates no relationship, obligation, or entitlement beyond what is set out here.