Report Security Issues
Help us keep dananoacard.com safe through coordinated, good-faith vulnerability disclosure.

If you believe you found a security vulnerability affecting dananoacard.com, please report it privately to DANANOA LLC. This policy defines which systems are in scope, the testing we authorize, how to submit a report, and the conditions for our bug bounty program.
Program Scope
In scope: The public-facing website and web application available at https://dananoacard.com/, but only to the extent the affected component is owned or directly controlled by DANANOA LLC.
Out of scope:
- Third-party infrastructure or services, including payment processors, hosting or CDN providers, email platforms, shipping providers, social networks, and vendor-operated systems
- Customer devices, customer accounts you do not own, employee devices or accounts, physical premises, and telephone systems
- Any domain, subdomain, API, mobile app, or system not expressly listed as in scope
A vulnerability in a third-party product may still be reported if it creates a demonstrable security impact on dananoacard.com, but do not test or access the third party's infrastructure. Ask us first if ownership or scope is unclear.
Authorization & Safe Harbor
When security research is conducted in good faith and fully complies with this policy, DANANOA considers that activity authorized with respect to the DANANOA-owned systems identified as in scope. We will not initiate civil action or request a criminal investigation solely because of an accidental, good-faith violation that is promptly reported and corrected.
This authorization does not apply to bad-faith conduct, intentional harm, extortion, privacy abuse, activity outside the defined scope, or violations of law. DANANOA cannot authorize testing of third-party systems or bind third parties, regulators, or law-enforcement agencies. You remain responsible for complying with applicable law.
Rules of Engagement
- Use only accounts and data you own or have explicit written permission to use.
- Use the minimum testing necessary to confirm a vulnerability. Do not continue exploitation to demonstrate additional impact.
- If you encounter personal, payment, authentication, confidential, or other sensitive data, stop immediately, do not copy or retain it, and report what occurred.
- Avoid service disruption, data modification, deletion, persistence, or any action that could affect customers or orders.
- Keep the vulnerability confidential until DANANOA provides written permission or a coordinated disclosure date.
- Delete any DANANOA data unintentionally obtained as soon as the report is submitted and safe deletion is possible.
Prohibited activities include:
- Denial-of-service, load, stress, or high-volume automated testing
- Social engineering, phishing, vishing, spam, credential stuffing, or brute-force attacks
- Malware, ransomware, destructive payloads, backdoors, persistence, or data exfiltration
- Physical attacks, employee targeting, extortion, threats, or demands for payment before disclosure
- Testing third-party systems, using stolen credentials or payment methods, or accessing another person's account or order
How to Report a Vulnerability
Email security@dananoacard.com with the subject line “Security Report.” Please include:
- The affected URL or component and a concise vulnerability summary
- Clear, reproducible steps using the minimum proof necessary
- The security impact and realistic attack scenario
- Relevant timestamps, sanitized screenshots, request or response details, and testing account information
- Any accidental access to data, service impact, or policy deviation
- Your preferred name for recognition and a reliable contact method
Do not email live malware, unredacted customer data, complete payment information, passwords, session tokens, or unnecessary personal information. We aim to acknowledge reports within 5 business days and provide an initial triage update within 10 business days. Remediation time depends on severity and complexity; these timeframes are service goals, not guarantees.
Bounty Eligibility
A report may qualify for a bounty only when all of the following conditions are met:
- You are the first person to privately report a previously unknown, reproducible, in-scope vulnerability.
- Your testing and disclosure fully comply with this policy and applicable law.
- The issue creates a meaningful security or privacy impact and is not already known, publicly disclosed, or reported by an automated scanner alone.
- You provide reasonable assistance needed to reproduce and understand the issue.
- You are legally eligible to receive payment and are at least 18 years old, or participate with permission from a parent or legal guardian.
- You are not a current employee, contractor, service provider, or household member of someone directly responsible for DANANOA's systems, unless we approve eligibility in writing.
Rewards are discretionary and stated as maximum amounts. DANANOA determines whether a report is valid, its severity, duplicate status, eligibility, and final reward based on demonstrated impact, exploitability, scope, and report quality.
Reward Guidelines
The examples below are guidance only. The maximum reward applies only to an eligible report with demonstrated impact at that severity.
- Remote code execution on a DANANOA-owned system
- Administrative authentication bypass or takeover
- Injection exposing sensitive customer data at scale
- Significant authorization or authentication bypass
- Stored XSS with meaningful impact on other users
- Exposure of sensitive internal or customer data
- Limited-impact insecure direct object reference
- CSRF with a meaningful security-sensitive action
- Business-logic flaw with demonstrated security impact
- Open redirects with demonstrated security impact
- Reflected XSS with meaningful exploitability
- Low-sensitivity information exposure with real impact
Normally Not Eligible for a Bounty
- Automated scanner output without a verified exploit and meaningful impact
- Missing security headers, cookie flags, version banners, TLS recommendations, or other best-practice observations without demonstrated impact
- Self-XSS, logout CSRF, clickjacking on pages without sensitive actions, open redirects, or user enumeration without additional security impact
- Rate-limiting observations without a practical security consequence
- Issues requiring obsolete browsers, unrealistic user interaction, compromised devices, stolen credentials, or physical access
- Denial-of-service findings, social engineering, spam, phishing, or vulnerabilities solely in third-party systems
- Duplicate, publicly known, previously reported, out-of-scope, or non-reproducible findings
We still welcome useful security observations even when they are not bounty-eligible.
Coordinated Disclosure & Program Changes
Do not disclose a vulnerability publicly or to others before receiving DANANOA's written permission or agreeing to a coordinated disclosure date. We may publish a sanitized summary after remediation. We will credit a researcher publicly only with the researcher's consent.
DANANOA may modify, pause, or end this program prospectively. Reports received before a change will normally be evaluated under the policy version in effect when submitted. Participation does not create employment, agency, or any payment obligation beyond a bounty expressly confirmed in writing.
Contact Information
Columbus, OH 43228, United States
Sunday: Closed
© 2026 DANANOA LLC. All Rights Reserved.







