RESPONSIBLE DISCLOSURE POLICY
The security of Booksy systems and data residing within them is crucial for us, and we treat potential security issues with a top priority. We do our best to protect the data of Booksy merchants and customers from security threats, and we encourage all users and security researchers to report security vulnerabilities discovered in our platform. Reports should be submitted through Intigriti, which will handle the first line of triage.
We are committed to handle vulnerability reports in a timely manner and the greatest attention, provided that the following Policy is respected.
I. SCOPE
- Booksy’s vulnerability disclosure program covers the following products:
- Booksy Customer Application - https://booksy.com/
- Booksy Business Application - https://booksy.com/pro/
- Booksy Mobile Applications:
- While Booksy develops a number of other products, we ask that all security researchers submit vulnerability reports only for the stated product list from point 1 above, subject to point 3 below.
- If you believe that you identified a critical risk vulnerability or potential data leakage which is not in scope from point 1 above, but still may negatively impact data of Booksy or its users, please do not hesitate to get in contact with us.
II. REPORTING AN ISSUE
- All the reports should be submitted through Intigriti via our dedicated VDP program there: https://app.intigriti.com/researcher/programs/booksy/booksyvdp
- When reporting, make sure to follow all the requirements from Intigriti. Include all details, steps for reproduction, affected assets and impact.
III. VULNERABILITY DISCLOSURE PROCEDURE
- You privately share the details of the security vulnerability with Intigriti and Security Team by reporting an issue, as described in point II (1) above.
- We acknowledge your submission and verify the vulnerability. In line with provided timelines on the VDP program page. Additional details might be required.
- Once a vulnerability is patched by our product team we notify you about the fix. For impactful vulnerabilities, some highs and criticals, we might add you to our Hall Of Fame, if you agree to.
IV. RULES OF ENGAGEMENT
- Detailed rules can be found on the Intigiti page. Here is a short version:
- do not store Booksy’s non-public data (except the data necessary to document and report the presence of a potential vulnerability);
- do not attempt to access or modify data that belongs to other Booksy user;
- do not attempt to execute denial of service attacks, or to compromise the reliability and availability of Booksy services;
- do not use scanners, automated tools or any other tools which may generate excessive traffic and negatively impact system’s availability;
- never attempt non-technical attacks such as social engineering, phishing, or physical attacks against anyone or any system;
- do not publicly disclose vulnerabilities without our prior consent (disclose only according to the disclosure procedure in point IV above).
V. WHAT TO REPORT
- In scope and out of scope vulnerabilities list is present on Intigtiti's page.
VII. HALL OF FAME
We would like to thank the following individuals for their contribution to increasing the overall Booksy’s security posture.
2022
- Takshal Patel
- Mubassir Patel
- Nikhil Rane
- Shivansh Khari
- Sam Crowther
- Opinder Singh
2023
- Mohamed Shibil
- Robert Muchacki
2025
- Gr3yG05T
- Harshvardhan Kumavat