At Bizexpanders LLC, we take the security of Tuga Futebol and our users' data seriously. priority. We welcome good-faith reports from security researchers that help us identify and address vulnerabilities in our services to help us maintain a safe platform.
If you believe you have found a security vulnerability affecting the Tuga Futebol website, mobile applications, or APIs, please report it to us promptly.
- How to Report a Vulnerability
Please send vulnerability reports to:
To help us investigate, include where available:
- A clear description of the vulnerability.
- The affected URL, app feature, API endpoint, or system.
- Steps to reproduce the issue.
- The potential impact of the vulnerability.
- Screenshots, logs, proof-of-concept code, or video recordings.
- Your contact details, if you would like us to respond or keep you updated.
Do not include unnecessary personal data, credentials, payment information, or other sensitive user information in your report. If sensitive information is necessary to demonstrate the issue, minimise it and clearly identify it as sensitive.
2. Scope
This policy applies to security research conducted in good faith against Tuga Futebol systems that are owned or controlled by Bizexpanders LLC, including:
- The Tuga Futebol website and associated subdomains.
- Official Tuga Futebol mobile applications.
- Tuga Futebol APIs and services made publicly available by Bizexpanders LLC.
This policy does not authorise testing of systems owned or controlled by third parties, including payment providers, app stores, hosting providers, advertising platforms, analytics providers, AI providers, email providers, social-media platforms, or sports-data providers.
For example, do not test Stripe, Apple, Google, DigitalOcean, MongoDB, OpenAI, OpenRouter, Perplexity, Meta, TikTok, Reddit, X, Resend, Sentryl, or any other third-party service. Report suspected Tuga Futebol integration issues to us, and report vulnerabilities in third-party systems directly to the relevant provider.
3. Good-Faith Security Research
We consider security research to be good faith when its primary purpose is to identify and report a vulnerability so that it can be remediated, and when it is conducted in accordance with this policy.
When investigating a suspected vulnerability, you must:
- Use the minimum testing necessary to confirm the issue.
- Stop testing and report the issue if you encounter personal data, confidential data, credentials, payment information, or other sensitive information.
- Avoid accessing, changing, downloading, deleting, or disclosing another person’s data.
- Avoid establishing persistent access, creating accounts without authorisation, escalating privileges, or moving laterally between systems.
- Keep vulnerability information confidential while we investigate and remediate the issue.
- Cooperate with reasonable requests for further information needed to reproduce and fix the vulnerability.
4. Prohibited Activity
You must not:
- Disrupt, degrade, or interfere with Tuga Futebol or another person’s use of the Services.
- Conduct denial-of-service, distributed-denial-of-service, stress, load, or volume testing.
- Use phishing, social engineering, impersonation, pretexting, or deceptive contact with our users, staff, contractors, or partners.
- Conduct physical-security testing, attempt unauthorised access to facilities, or test employee devices.
- Access, collect, alter, delete, publish, sell, or exfiltrate personal data or confidential information.
- Upload malware, ransomware, harmful code, or files intended to disrupt or compromise systems.
- Perform testing against third-party systems or providers.
- Publicly disclose, sell, exploit, or share a vulnerability before we have had a reasonable opportunity to investigate and address it.
- Demand payment, threaten disclosure, or use a vulnerability for commercial leverage.
5. Safe Harbour
If you make a good-faith effort to comply with this policy while conducting security research, Bizexpanders LLC will consider that research authorised for the limited purpose of this policy.
Bizexpanders LLC will not initiate or support civil legal action against you for good-faith research conducted in accordance with this policy. If a third party initiates legal action relating to research that complied with this policy, we may make this authorisation known, where appropriate.
This safe-harbour commitment applies only to claims under Bizexpanders LLC’s control. It does not authorise activity that is unlawful, harmful, conducted in bad faith, violates another party’s rights, involves third-party systems, or breaches this policy.
6. Our commitment
For reports submitted in accordance with this policy, we aim to:
- Acknowledge receipt within 5 business days.
- Assess the report and determine its priority.
- Keep you reasonably informed of our progress where you provide contact details.
- Notify you when the issue has been resolved, where appropriate.
- Coordinate in good faith on any public disclosure after remediation.
We do not currently operate a paid bug-bounty programme. Reporting a vulnerability does not create an entitlement to payment, compensation, recognition, or public credit.
7. Coordinated disclosure
Please give us a reasonable opportunity to investigate and remediate a vulnerability before publicly disclosing it.
We generally ask researchers not to publicly disclose a vulnerability until we have confirmed that a fix is available or we have agreed a coordinated disclosure timeline. The appropriate timeframe depends on the severity, complexity, user impact, and availability of a fix.
8. Contact
For security vulnerabilities affecting Tuga Futebol, contact:
For non-security privacy, legal, or account matters, contact:
