Piickr Security Policy
Keeping user accounts, market data, and infrastructure safe is core to how Piickr operates. This page describes our security practices and how to responsibly report a vulnerability.
1. Account Security — Your Part
- Use a strong, unique password for your Piickr account and enable two-factor authentication if offered.
- Never share your login credentials, API keys, or session tokens with anyone.
- Log out of shared or public devices after use.
2. Reporting a Vulnerability
If you believe you've found a security vulnerability in Piickr (e.g. authentication bypass, data exposure, injection flaw, broken access control), please report it privately before disclosing it publicly.
3. What We Ask
- Give us a reasonable time to investigate and remediate before any public disclosure.
- Do not access, modify, or delete data belonging to other users.
- Do not run automated scanners that degrade Service performance for other users; use a test account where possible.
- Do not attempt social engineering, phishing, or physical attacks against Piickr staff or users.
4. Our Commitment (Safe Harbor)
If you make a good-faith effort to comply with this policy while researching a vulnerability, we will not pursue legal action against you for that research, and we will work with you to understand and resolve the issue quickly. We aim to acknowledge reports within 48 hours.
5. Out of Scope
- Vulnerabilities in third-party services we link to but do not operate.
- Issues requiring physical access to a user's device.
- Reports generated purely by automated scanning tools without a demonstrated, reproducible impact.
6. Incident Notification
In the event of a confirmed data breach affecting user accounts, we will notify affected users and take reasonable steps as required by applicable law, consistent with our Privacy Policy.