360mods is committed to ensuring the highest levels of security and privacy for the millions of families who rely on our platform every day. We actively value the contributions of independent cybersecurity researchers and ethical hackers.
Safe Harbor Commitment
We consider research conducted in accordance with this policy to be authorized and protected under our Safe Harbor terms. If you act in good faith, avoid violating the privacy of our members, do not disrupt our production services, and give our engineering team reasonable time to remediate before public disclosure, we will not pursue legal action against you.
< 24 Hours
Initial SLA Response & Receipt
< 72 Hours
Triage & Engineering Severity Assessment
Every 7 Days
Remediation Status Update
In-Scope Assets
- 360mods Mobile Applications (iOS and Android client builds)
- Core API endpoints and cloud services (
*.360mods.net) - Tile Bluetooth Low Energy protocol and firmware implementation
- Pet Safety cellular trackers and device telematics bridges
Out-of-Scope Activities
- Denial of Service (DoS/DDoS) attacks against production servers
- Social engineering, phishing, or physical attacks on 360mods staff or facilities
- Executing automated vulnerability scans that generate excessive server load
- Accessing, downloading, or modifying member personal data beyond what is strictly necessary to demonstrate a proof-of-concept
How to Submit a Vulnerability Report
Please email your detailed report to [email protected] including:
- Clear step-by-step reproduction steps and environmental prerequisites.
- A working proof-of-concept (PoC) script or screenshots where applicable.
- Your assessment of potential impact and suggested mitigation steps.