Skip to main content

Security

Security

We welcome reports from security researchers. This page explains how to reach us and what to expect.

Effective
August 2, 2026
Applies to
buhalon.com

Reporting a vulnerability

Send reports to [email protected]. Please include enough detail for us to reproduce the issue: the affected URL or component, the steps you took, and what you observed.

Report only what you have found yourself, and please do not post details publicly before we have had a chance to respond.

What to expect from us

  • We aim to acknowledge reports within five business days.
  • We will tell you whether we consider the issue valid and in scope.
  • We will keep you informed while we work on a fix, and let you know when it ships.
  • We will credit you if you would like to be credited, once the issue is resolved.

Safe testing boundaries

If you follow these boundaries in good faith, we will treat your research as authorized and will not pursue action against you for it.

  • Test only against buhalon.com. Do not test Kusinely production systems, merchant accounts, or customer data under this page — contact us first.
  • Do not access, modify, or exfiltrate data that is not your own. If you encounter personal data, stop and report it.
  • Do not run denial-of-service, volumetric, or load-generating tests.
  • Do not use social engineering, phishing, or physical intrusion against our people or providers.
  • Do not use automated scanners that generate high request volumes.

Rewards

Buhalon does not currently run a paid bug bounty program, and we cannot promise a monetary reward for a report. We will say so clearly here if that changes.

Scope

This page covers the Buhalon corporate website. We do not publish details of our internal infrastructure, providers, or architecture here.