Last updated: 2 September 2026
Security Policy
We welcome good-faith reports of security issues in Eyeban products and eyeban.ir. This policy explains how to report and what to expect.
1. How to report
Email hello@eyeban.ir with a clear description, steps to reproduce, affected URLs or versions, and impact. Do not include customer source code unless we ask for a minimal sample. Encrypt sensitive details if you can, and give us a contact method for follow-up.
2. In scope
In scope: eyeban.ir web application, authentication and account flows we operate, and officially published Eyeban desktop builds.
Out of scope for this policy: social engineering of staff, physical attacks, denial-of-service, and reports against third-party services we do not control.
Out of scope for this policy: social engineering of staff, physical attacks, denial-of-service, and reports against third-party services we do not control.
3. Our process
We will acknowledge valid reports when practical, investigate, and remediate based on severity. We do not currently operate a public bug bounty with fixed payouts. We may recognize helpful reporters with credit if you want it and disclosure will not increase risk.
4. Safe harbor
If you research in good faith, avoid privacy violations and service disruption, and promptly report findings to us without exploiting them beyond what is needed to demonstrate the issue, we will not pursue legal action for that research. This safe harbor does not authorize access to other users’ data or systems beyond Eyeban assets in scope.
5. Contact
Security: hello@eyeban.ir