Security & Vulnerability Disclosure Policy
Cryptographic standards, infrastructure defenses, and our Safe Harbor vulnerability reporting program.
1. Technical Security Measures
Encryption: All web traffic is strictly encrypted using TLS 1.3. User passwords and API secrets are hashed and stored using modern cryptographic algorithms (Argon2, AES-256-GCM).
Infrastructure Defense: Web Application Firewalls (WAF), rate limiting, automated anomaly detection, and continuous security monitoring.
Session Governance: Two-factor authentication support, remote session revocation, and API key rotation safeguards.
2. Responsible Vulnerability Disclosure (Safe Harbor)
WinSell values the contributions of the security research community in maintaining platform safety.
If you discover a potential vulnerability, please submit a detailed report with reproduction steps (PoC) to security@winsell.vn.
WinSell Safe Harbor Commitment: We will not pursue legal action against security researchers who:
- Do not access, modify, or destroy another user's actual personal data.
- Do not cause service degradation or disruption (no DoS/DDoS).
- Provide WinSell at least thirty (30) days to remediate the issue before public disclosure.
Đơn vị chịu trách nhiệm pháp lý
Doanh nghiệp:
CÔNG TY TNHH WINSELLMã số thuế:
1801831784Đại diện theo pháp luật:
Trương Quốc HưngĐịa chỉ đăng ký:
Thành phố Cần Thơ, Việt NamEmail liên hệ:
support@winsell.vnEmail DPO (Bảo vệ dữ liệu):
privacy@winsell.vn