Security and Vulnerability Reporting Policy

Effective date: July 24, 2026
Last updated: July 24, 2026

BareAnime values the work of security researchers and members of the public who help identify vulnerabilities that could affect our website, accounts, store, community features, or users.

This Security and Vulnerability Reporting Policy explains how to report a suspected security vulnerability, which systems and testing methods are authorized, which activities are prohibited, and how BareAnime intends to work with good-faith researchers.

In this policy:

  • “BareAnime,” “we,” “us,” and “our” refer to BareAnime.
  • “Services” refers to BareAnime.com, Shop.BareAnime.com, member accounts, public profiles, theory-submission features, comments, newsletters, store functions, APIs, and other BareAnime-controlled services.
  • “Researcher,” “you,” and “your” refer to a person conducting security research or submitting a vulnerability report.
  • “Vulnerability” means a weakness that could compromise the confidentiality, integrity, availability, privacy, security, or proper operation of a system or its data.
  • “Good-Faith Research” means security testing performed to identify, report, and help correct a vulnerability while avoiding harm, unnecessary access, disruption, privacy violations, and exploitation.
  • “Sensitive Data” includes passwords, authentication tokens, payment information, private communications, unpublished drafts, personal information, security logs, private account data, and other nonpublic information.

This policy does not create a bug-bounty program or promise payment.

1. Purpose of This Policy

BareAnime wants security concerns reported safely and privately so that they can be investigated and addressed before users are harmed.

This policy is intended to:

  • Provide a clear security-reporting channel
  • Encourage responsible vulnerability disclosure
  • Define authorized research activity
  • Reduce accidental harm
  • Protect user privacy
  • Prevent public exploitation
  • Distinguish good-faith research from abuse
  • Explain how reports may be handled

2. Good-Faith Security Research

BareAnime considers research to be conducted in good faith when the researcher:

  • Acts primarily to improve security
  • Tests only systems authorized by this policy
  • Avoids harm to users and the public
  • Uses the minimum testing necessary
  • Stops after confirming the vulnerability
  • Avoids unnecessary access to data
  • Does not exploit the vulnerability for personal gain
  • Reports the issue promptly and privately
  • Provides BareAnime a reasonable opportunity to investigate
  • Follows this policy and applicable law

Testing performed for extortion, fraud, theft, harassment, sabotage, unauthorized surveillance, or competitive advantage is not Good-Faith Research.

3. Safe-Harbor Statement

When you conduct Good-Faith Research in accordance with this policy, BareAnime will treat your activity as authorized for the limited purpose of identifying and reporting a security vulnerability.

BareAnime does not intend to initiate legal action against a researcher solely for accidental, good-faith activity that:

  • Remains within this policy
  • Does not cause material harm
  • Does not involve data theft
  • Does not involve extortion
  • Is promptly disclosed
  • Stops when requested

If a third party initiates legal action arising from research conducted in compliance with this policy, BareAnime may state that the activity was authorized under this policy when the facts support that conclusion.

This statement applies only to BareAnime’s own rights and claims. BareAnime cannot authorize activity against systems owned by another party or prevent independent third parties or government authorities from taking action.

Nothing in this policy authorizes conduct prohibited by applicable law.

4. Systems Generally in Scope

Unless BareAnime publishes a narrower scope notice, the following BareAnime-controlled public systems may be tested:

  • BareAnime.com
  • Public pages on Shop.BareAnime.com
  • BareAnime registration and login functions
  • Public profile features
  • Theory-submission interfaces
  • Comment and reporting interfaces
  • BareAnime-controlled contact forms
  • BareAnime-controlled APIs made publicly available
  • Other publicly accessible systems that BareAnime expressly identifies as in scope

Testing must remain limited to accounts, data, and resources that you own or have explicit permission to use.

5. Systems and Services Out of Scope

The following are out of scope unless BareAnime gives you written authorization:

  • Third-party hosting infrastructure
  • WordPress.com systems not owned by BareAnime
  • WordPress core infrastructure
  • WooCommerce infrastructure not controlled by BareAnime
  • Payment processors
  • Banks or card networks
  • Shipping and fulfillment providers
  • Email-delivery providers
  • Advertising networks
  • Analytics providers
  • Affiliate retailers
  • Social-media platforms
  • YouTube
  • Cloud-service provider infrastructure
  • Domain registrars
  • Content-delivery networks
  • Internet-service providers
  • Third-party plugins or themes outside BareAnime’s implementation
  • Employee or contractor personal accounts
  • Physical offices, homes, devices, or networks

A vulnerability in a third-party product may be reported to BareAnime when it directly affects BareAnime, but you must not test the third party’s wider infrastructure without its permission.

6. Third-Party Components

BareAnime may rely on WordPress themes, plugins, payment tools, account services, and other third-party components.

When you identify a vulnerability in a third-party component:

  • Report the BareAnime-specific impact to BareAnime.
  • Avoid testing unrelated websites using the same component.
  • Follow the vendor’s own disclosure policy where appropriate.
  • Do not publicly identify unpatched BareAnime installations.
  • Do not access third-party systems without authorization.

BareAnime may forward relevant information to the vendor or hosting provider.

7. Authorized Testing Methods

Good-faith testing may include:

  • Reviewing publicly delivered HTML, CSS, and JavaScript
  • Testing your own BareAnime account
  • Testing access controls between two accounts you own
  • Submitting nonharmful test values to public forms
  • Verifying whether a suspected issue exists
  • Testing ordinary authentication and session behavior
  • Examining security headers
  • Testing input validation with harmless payloads
  • Reviewing public API responses
  • Confirming whether public information is unintentionally exposed
  • Limited automated scanning that does not disrupt the Services

Testing should use the least invasive method capable of confirming the issue.

8. Stop After Confirmation

Once you have confirmed that a vulnerability exists, stop testing.

Do not:

  • Expand access to additional accounts
  • Download more data
  • Increase privilege beyond what is necessary
  • Maintain persistent access
  • Explore unrelated systems
  • Attempt to determine the maximum possible harm
  • Continue testing after BareAnime asks you to stop

A screenshot, response header, limited sample, or carefully redacted record will often be enough to demonstrate the issue.

9. Use Test Accounts

Whenever possible, use accounts you created specifically for testing.

Do not test against:

  • Another member’s account
  • A BareAnime administrator account
  • A staff account
  • An account belonging to a minor
  • A customer’s order
  • An unrelated email address
  • Another person’s profile or private content

When testing authorization boundaries, use two or more accounts you personally control.

10. Data Minimization

Access only the minimum information necessary to demonstrate the vulnerability.

If you unexpectedly encounter Sensitive Data:

  • Stop accessing the affected area.
  • Do not open additional records.
  • Do not download a database or collection.
  • Do not copy unnecessary information.
  • Do not share the information.
  • Report the issue promptly.
  • Delete locally stored copies after BareAnime confirms they are no longer needed.

Proof should be redacted whenever possible.

11. Personal Information

You may not intentionally access, collect, retain, alter, disclose, or publish another person’s personal information.

Personal information may include:

  • Names
  • Email addresses
  • IP addresses
  • Account identifiers
  • Password data
  • Authentication tokens
  • Private profile information
  • Location information
  • Purchase history
  • Support communications
  • Private messages
  • Unpublished theory drafts
  • Information concerning minors

If personal information appears unexpectedly, stop testing and notify BareAnime immediately.

12. Authentication Credentials

Do not attempt to obtain or use credentials belonging to another person.

Prohibited credential activity includes:

  • Phishing
  • Credential stuffing
  • Password spraying
  • Purchasing stolen credentials
  • Using leaked password databases
  • Social engineering
  • Resetting another user’s password
  • Intercepting authentication codes
  • Stealing session cookies
  • Reusing tokens from another user

You may test password-reset and authentication behavior only with accounts and email addresses you control.

13. Prohibited Testing

The following activities are not authorized:

  • Denial-of-service testing
  • Distributed denial-of-service testing
  • Deliberate service degradation
  • High-volume traffic generation
  • Resource-exhaustion attacks
  • Destructive testing
  • Malware deployment
  • Ransomware
  • Data destruction
  • Data alteration
  • Database dumping
  • Mass account access
  • Credential attacks
  • Phishing
  • Social engineering
  • Physical intrusion
  • Employee impersonation
  • Extortion
  • Threats
  • Public exploitation
  • Persistent unauthorized access
  • Installing backdoors
  • Testing against minors’ accounts
  • Testing third-party systems without authorization
  • Purchasing stolen data
  • Intentionally violating another person’s privacy

14. Denial-of-Service and Load Testing

Do not conduct:

  • Stress testing
  • Load testing
  • Traffic flooding
  • Request amplification
  • Bandwidth exhaustion
  • Storage exhaustion
  • Email flooding
  • Comment flooding
  • Registration flooding
  • Checkout flooding
  • Automated activity likely to affect availability

Even a technically valid vulnerability report may fall outside safe harbor when testing causes avoidable disruption.

15. Automated Scanning

Limited automated scanning is permitted only when it:

  • Uses a reasonable request rate
  • Does not degrade performance
  • Does not create accounts in bulk
  • Does not submit excessive forms
  • Does not trigger email floods
  • Does not generate large log volumes
  • Does not access personal information
  • Can be stopped promptly

BareAnime may block or rate-limit scanning traffic without determining that the researcher acted maliciously.

A block is not permission to bypass the restriction.

16. Social Engineering

Do not attempt to manipulate BareAnime staff, contractors, members, vendors, or support personnel into:

  • Revealing credentials
  • Resetting accounts
  • Disclosing security information
  • Opening attachments
  • Installing software
  • Visiting malicious links
  • Changing payment details
  • Providing private information
  • Granting administrative access

Social engineering is outside the authorized scope of this policy.

17. Physical Security Testing

This policy does not authorize:

  • Entering offices or private property
  • Accessing personal devices
  • Searching discarded materials
  • Tampering with mail
  • Following staff
  • Recording private conversations
  • Testing locks
  • Connecting devices to private networks

Report physical-security concerns without attempting to exploit them.

18. Payment and Checkout Systems

Do not test payment systems using:

  • Stolen payment details
  • Real unauthorized cards
  • Fraudulent chargebacks
  • Attempts to avoid payment
  • Refund manipulation
  • Coupon abuse
  • Order manipulation affecting another customer
  • Unauthorized payment-provider testing

Use only your own payment information and ordinary low-risk transactions where necessary.

Vulnerabilities involving a payment processor should also be reported to the processor under its own policy.

19. Store and Order Information

Do not access, alter, cancel, redirect, or refund another customer’s order.

If you identify a possible order-access vulnerability:

  • Use only orders you placed.
  • Stop after confirming the access-control issue.
  • Do not retrieve unrelated customer records.
  • Report the issue privately.

20. Member Content and Drafts

Do not access another member’s:

  • Unpublished theory
  • Private draft
  • Moderation record
  • Private profile field
  • Support request
  • Message
  • Account settings
  • Uploaded file not intended for public access

If such content becomes visible unexpectedly, stop and report the issue.

21. Vulnerabilities Involving Minors

Exercise heightened caution when a vulnerability may expose information about minors.

Do not:

  • Access additional minor accounts
  • Contact the affected minor
  • Save identifying information
  • Publish screenshots containing minor information
  • Attempt to verify identity independently
  • Share the information with unrelated parties

Report the issue immediately with all identifying information redacted where possible.

22. Examples of Useful Reports

Reports are especially useful when they concern:

  • Authentication bypass
  • Account takeover
  • Broken access control
  • Exposure of private member information
  • Exposure of unpublished theories
  • Cross-site scripting
  • SQL injection
  • Server-side request forgery
  • Remote-code execution
  • File-upload vulnerabilities
  • Privilege escalation
  • Cross-site request forgery with material impact
  • Insecure direct-object references
  • Sensitive data exposure
  • Security misconfiguration with demonstrated impact
  • Payment or order-access weaknesses
  • Admin-interface exposure
  • Vulnerable API authorization
  • Circumvention of privacy settings
  • Unauthorized modification or deletion of content

23. Reports That May Not Require Action

The following may not be treated as security vulnerabilities unless accompanied by meaningful, demonstrated impact:

  • Missing security headers without an exploit
  • Version-number disclosure
  • Public information indexed by a search engine
  • Username enumeration without additional risk
  • Self-cross-site scripting
  • Clickjacking on a page without sensitive actions
  • Logout cross-site request forgery
  • Rate-limit concerns without demonstrated impact
  • Email spoofing reports without domain-specific evidence
  • Software versions that are not actually vulnerable
  • Best-practice recommendations without a security consequence
  • Issues requiring physical access to the researcher’s own device
  • Reports generated solely by an automated scanner
  • Hypothetical vulnerabilities without reproducible evidence
  • Content or editorial disagreements
  • Spam that does not involve a security flaw
  • Broken links
  • Ordinary account-support issues

BareAnime may still consider these reports as product or configuration feedback.

24. Security Report Requirements

A useful report should include:

  • Your name or chosen researcher name
  • A reliable contact email address
  • The affected domain, page, endpoint, or feature
  • The type of vulnerability
  • A clear description of the issue
  • Reproduction steps
  • The expected behavior
  • The actual behavior
  • The potential impact
  • The date and approximate time of testing
  • The account or test identifiers you controlled
  • Screenshots or limited evidence where helpful
  • Suggested remediation, if known
  • Whether Sensitive Data was encountered
  • Whether you retained any data
  • Your intended disclosure plans, if any

Do not include unnecessary personal information belonging to users.

25. Proof-of-Concept Material

Proof-of-concept material should be:

  • Limited
  • Non-destructive
  • Redacted
  • Reproducible
  • Necessary to explain the issue

Do not send:

  • Complete databases
  • Password lists
  • Authentication tokens belonging to users
  • Full payment details
  • Malware
  • Active ransomware
  • Personal information unrelated to the report
  • Child sexual abuse material
  • Pirated material
  • Large archives of user content

Ask BareAnime before sending a large or sensitive attachment.

26. Where to Send Reports

Send security reports to:

BareAnime Security
Website: BareAnime.com
Email: [INSERT DEDICATED SECURITY EMAIL, PREFERABLY security@bareanime.com]
Recommended subject: Security Vulnerability Report — [BRIEF ISSUE NAME]

Do not submit vulnerabilities through:

  • Public comments
  • Member profiles
  • Social-media replies
  • Theory submissions
  • Product reviews
  • Public forums
  • Ordinary copyright forms

If a dedicated security address is not yet available, use BareAnime’s main contact email with the subject line above.

27. Encryption

BareAnime may publish a PGP key or another encrypted reporting method in the future.

Until then:

  • Do not send large amounts of Sensitive Data through ordinary email.
  • Redact personal information.
  • Describe the issue first.
  • Ask for a secure transfer method when necessary.

The absence of an encrypted channel does not authorize public disclosure of sensitive details.

28. BareAnime’s Review Process

After receiving a report, BareAnime may:

  • Confirm receipt
  • Request clarification
  • Attempt to reproduce the issue
  • Assess severity
  • Review logs
  • Contact a host, developer, plugin provider, or vendor
  • Apply a temporary mitigation
  • Develop or request a fix
  • Test the fix
  • Monitor for exploitation
  • Notify affected users where required
  • Consult legal, privacy, or security professionals
  • Close reports that cannot be reproduced

BareAnime may prioritize reports based on risk rather than order of receipt.

29. No Fixed Resolution Deadline

BareAnime will make reasonable efforts to investigate legitimate security reports.

Resolution may depend on:

  • Severity
  • Technical complexity
  • Availability of a patch
  • Third-party provider involvement
  • Testing requirements
  • Risk of service interruption
  • Whether user notification is legally required
  • The need to preserve evidence

This policy does not guarantee that every issue will be corrected or resolved within a particular period.

30. Communication with Researchers

BareAnime may communicate with a researcher about:

  • Reproduction steps
  • Scope
  • Severity
  • Mitigation
  • Remediation
  • Disclosure timing
  • Attribution
  • Report closure

BareAnime may limit technical details when disclosure could increase risk or expose information about another user.

Researchers should use the same email thread when providing updates.

31. Coordinated Disclosure

BareAnime asks researchers not to publicly disclose vulnerability details until:

  • BareAnime has investigated the report
  • A fix or reasonable mitigation has been implemented
  • A mutually reasonable disclosure date has been discussed
  • Immediate user risk has been reduced

The researcher and BareAnime may agree on:

  • A publication date
  • A limited technical summary
  • Redactions
  • A credit statement
  • Coordination with a third-party vendor
  • Delayed disclosure when users remain at risk

BareAnime will not require indefinite silence as a condition of good-faith reporting.

32. Public Disclosure Without Coordination

Publicly disclosing an uncorrected vulnerability before BareAnime has a reasonable opportunity to investigate may:

  • Increase risk to users
  • Enable criminal exploitation
  • Interfere with remediation
  • Remove the activity from the protection of this policy
  • Lead BareAnime to take protective or legal action where appropriate

Emergency disclosure to an appropriate regulator, law-enforcement authority, or affected provider may be appropriate in limited circumstances.

33. Researcher Recognition

BareAnime may, with the researcher’s permission:

  • Thank the researcher privately
  • List the researcher on a security acknowledgments page
  • Credit a public advisory
  • Link to the researcher’s professional profile
  • Provide a written acknowledgment

BareAnime will not intentionally publish a researcher’s legal name or contact information without permission, except where legally required.

34. Anonymous Reports

BareAnime may accept anonymous or pseudonymous reports.

However, anonymity may make it harder to:

  • Request clarification
  • Verify findings
  • Coordinate disclosure
  • Provide recognition
  • Notify the researcher of remediation

Anonymous reports should still contain sufficient technical detail.

35. No Bug-Bounty Program

BareAnime does not currently operate a paid bug-bounty program.

Submitting a report does not create a right to:

  • Payment
  • A reward
  • Merchandise
  • Employment
  • Contract work
  • Public credit
  • Reimbursement
  • Revenue sharing

Do not demand payment or threaten disclosure as a condition of reporting.

BareAnime may voluntarily offer recognition or a reward, but no reward is promised unless BareAnime establishes separate written terms.

36. Extortion and Payment Demands

The following are not Good-Faith Research:

  • Demanding payment before revealing basic details
  • Threatening to sell the vulnerability
  • Threatening to expose user data
  • Threatening immediate public disclosure to force payment
  • Demanding employment
  • Demanding merchandise or services
  • Withholding deletion of copied data
  • Requesting payment in exchange for not exploiting the issue

A researcher may ask whether a reward program exists, but may not use threats or retained access as leverage.

37. Data Retention by Researchers

Researchers should delete:

  • User data
  • Screenshots containing Sensitive Data
  • Authentication tokens
  • Temporary files
  • Local database records
  • Copies of unpublished content

after BareAnime confirms that the evidence is no longer needed.

Where immediate deletion is necessary to protect users, delete the data after documenting only the minimum technical information required for the report.

Do not retain user data for a portfolio, presentation, demonstration, or future research.

38. Security Incidents and Breaches

A vulnerability report may reveal an active security incident.

If you observe evidence of ongoing exploitation:

  • Stop testing.
  • Notify BareAnime immediately.
  • Identify the evidence without expanding access.
  • Do not contact affected users directly.
  • Do not engage with the apparent attacker.
  • Preserve only minimal relevant evidence.

BareAnime may activate its incident-response procedures and involve service providers, legal counsel, insurers, or authorities.

39. Legal and Regulatory Notifications

BareAnime will evaluate whether a confirmed incident requires notice to:

  • Affected individuals
  • Regulators
  • Law-enforcement authorities
  • Payment providers
  • Hosting providers
  • Business partners
  • Insurers
  • Other legally required recipients

A researcher should not make legal conclusions on BareAnime’s behalf.

40. Reports Concerning Illegal Content

A security-reporting channel should not be used to transmit illegal material.

If a vulnerability exposes suspected child sexual abuse material or similarly prohibited content:

  • Do not download it.
  • Do not forward it.
  • Do not include it as an attachment.
  • Record only the necessary page or technical location.
  • Report the issue immediately.
  • Follow applicable reporting requirements.

41. Intellectual-Property Rights

Submitting a vulnerability report does not transfer ownership of the researcher’s original report or tools to BareAnime.

However, you grant BareAnime permission to:

  • Review the report
  • Reproduce the issue internally
  • Share necessary details with service providers and advisers
  • Use the information to remediate the vulnerability
  • Retain records for security and legal purposes
  • Publish an agreed or appropriately redacted advisory

Do not submit third-party confidential information without authorization.

42. Confidential Information

BareAnime may share report information with:

  • Hosting providers
  • Developers
  • Plugin or theme vendors
  • Security consultants
  • Legal counsel
  • Insurers
  • Payment providers
  • Regulators
  • Law-enforcement authorities
  • Other parties reasonably necessary to address the issue

BareAnime will seek to limit disclosure to what is reasonably necessary.

Do not assume that a report creates an attorney-client, fiduciary, employment, or nondisclosure relationship.

43. Researcher Privacy

BareAnime may collect information supplied in a security report, including:

  • Name or alias
  • Email address
  • Technical information
  • IP address
  • Testing records
  • Communications
  • Supporting evidence

This information may be used to:

  • Investigate the report
  • Communicate with the researcher
  • Prevent abuse
  • Correct vulnerabilities
  • Maintain legal and security records
  • Coordinate disclosure

Information will be handled according to BareAnime’s Privacy Policy.

44. Policy Violations

Activity may fall outside this policy when a researcher:

  • Tests an out-of-scope system
  • Accesses unnecessary user information
  • Causes disruption
  • Uses stolen credentials
  • Installs persistence
  • Refuses to stop
  • Publishes exploit details irresponsibly
  • Threatens BareAnime
  • Demands payment through coercion
  • Alters or deletes data
  • Engages in fraud
  • Violates another person’s rights
  • Acts primarily for harmful purposes

BareAnime may respond through technical blocks, account restrictions, provider reports, legal processes, or law enforcement when appropriate.

45. Accidental Policy Deviations

BareAnime recognizes that good-faith researchers may make minor accidental mistakes.

If you accidentally:

  • Access limited unexpected data
  • Send more requests than intended
  • Trigger an email
  • Modify your own test record unexpectedly
  • Enter an unintended system area

stop immediately, report what happened, and avoid further access.

BareAnime will consider your intent, conduct, harm, transparency, and cooperation when evaluating the incident.

46. Security Is Not Guaranteed

BareAnime uses reasonable efforts to protect its Services, but no website or online system is completely secure.

This policy does not guarantee that:

  • All vulnerabilities will be discovered
  • All reports will be valid
  • Every vulnerability will be fixed
  • No breach will occur
  • Third-party providers will be free from vulnerabilities
  • The Services will always remain available

Users should maintain strong passwords and follow BareAnime’s account-security guidance.

47. Changes to Scope

BareAnime may:

  • Add systems to scope
  • Remove systems from scope
  • Temporarily suspend testing
  • Establish request-rate restrictions
  • Publish more specific testing rules
  • Introduce a bug-bounty program
  • Change the reporting address

Researchers should review the current version of this policy before beginning new testing.

48. Changes to This Policy

BareAnime may update this policy when:

  • Website systems change
  • Account features expand
  • Store systems change
  • New service providers are added
  • Security practices change
  • New threats emerge
  • Applicable law changes
  • A bug-bounty program is introduced

The “Last updated” date identifies the current version.

49. Contact Information

To report a vulnerability, contact:

BareAnime Security
Website: BareAnime.com
Email: Contact@bareanime.com
Location: United States

Subject: Security Vulnerability Report — [BRIEF ISSUE NAME]

For ordinary account problems, copyright notices, content complaints, or editorial corrections, use the relevant BareAnime contact category rather than the security-reporting address.