Vulnerability disclosure policy
At Pet Media Group, including Pets4Homes, Lancaster Puppies, Annunci Animali, Mundo Animalia, Hästnet and Puppyplaats, the safety and privacy of our community of pet lovers, breeders and buyers is our top priority.
If you are a security researcher and have discovered a vulnerability in our platforms, we appreciate your help in disclosing it to us responsibly. We commit to working with you to validate and fix the issue promptly.
security@petmediagroup.comSafe harbour
If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorised. We will not take legal action against you, nor will we ask law enforcement to investigate you, provided you adhere to the guidelines below.
Guidelines and rules of engagement
To keep our users safe and maintain authorised status under this policy, you must adhere to the following rules.
Prompt reporting
Report the vulnerability to us as soon as possible after discovery. You must not delay reporting to attempt further exploitation, find external buyers, or hoard the vulnerability. Reports should ideally be submitted within 72 hours of initial discovery.
No deep diving or lateral movement
Once you have established that a vulnerability exists, for example verifying an open path or a basic SQL injection, stop your research immediately. Do not attempt to pivot to other internal systems, elevate privileges, download data, or probe further into our network. Your proof of concept should be minimal and non-destructive.
No data disruption
Avoid scanning techniques that cause a denial of service, alter data, or degrade our services for real users.
Respect user privacy
Do not access, modify, download, or retain data belonging to other users. If you accidentally access personally identifiable information, stop immediately and securely delete any local copies.
No extortion
Do not attempt to extort Pet Media Group or demand payment in exchange for withholding a vulnerability.
Coordinated disclosure timeline
We believe in coordinated vulnerability disclosure. To protect our community, we ask that you do not share details of the vulnerability publicly or with any third party until either we have formally acknowledged, remediated and verified the fix, or a standard window of 90 days has passed from your initial report, whichever comes first.
If our team requires more time due to the complexity of the fix, we will communicate this with you transparently to discuss an extension.
Scope
This policy applies to security vulnerabilities found within the core digital assets owned and operated by Pet Media Group.
In scope
- *.petmediagroup.com
- *.pets4homes.co.uk
- *.lancasterpuppies.com
- *.annuncianimali.it
- *.mundoanimalia.com
- *.hastnet.se
- *.puppyplaats.nl
- Associated mobile applications (iOS and Android) for the above brands
- Primary APIs powering these platforms
Out of scope
- Third-party integrations or services hosted by providers not directly managed by Pet Media Group, for example third-party payment gateways and external help desks.
- Social engineering, phishing, or physical security attacks against Pet Media Group employees or offices.
- Spam, text injection, or UI/UX bugs without a clear security impact, for example missing security headers or missing SPF/DKIM records without evidence of spoofing.
How to submit a report
Please email your findings to security@petmediagroup.com. To help us triage your report as quickly as possible, your email should include:
- Platform affected: clearly state which marketplace or domain the issue impacts.
- Description: a clear explanation of the vulnerability and its potential impact.
- Proof of concept: step-by-step instructions, scripts or screenshots showing how to reproduce the issue. Please keep proofs of concept non-destructive.
If you wish to encrypt your report, please request our PGP public key via a brief initial email.
Our commitment to you
If you play by the rules, we promise to:
- Acknowledge receipt of your report within 3 business days.
- Provide a primary point of contact and keep you updated as we investigate and validate the issue.
- Notify you once the vulnerability has been resolved.
- With your permission, credit you publicly for your contribution to keeping our pet loving community safe. We currently operate a recognition-only policy and do not offer monetary bug bounties at this time.