Legal · Responsible Disclosure
Blossom Responsible Disclosure Policy
Version 0.1 — Last updated July 22, 2026
Polymath HQ, Inc. d/b/a Blossom welcomes good-faith reports that help protect our customers, users, and systems. This policy describes authorized security research, how to report a vulnerability, and Blossom’s safe-harbor commitment.
1. Scope
In short: Test only Blossom systems you can identify as public and in scope, using your own accounts and the minimum access needed to confirm an issue.
This policy covers publicly accessible websites, applications, and APIs operated by Blossom under the blossom.fm domain, unless a page or service says it is excluded. A third-party service, Customer-Connected Service, vendor system, customer deployment, employee device, or unrelated domain is outside scope even if it integrates with Blossom.
If you are unsure whether a system is in scope, ask legal@blossom.fm before testing.
2. Rules for good-faith research
In short: Avoid harm, privacy invasion, persistence, disruption, and unnecessary data access. Stop once you can demonstrate the issue.
To qualify under this policy, you must:
- make a good-faith effort to comply with this policy and applicable law;
- use accounts and organizations you own or have express permission to test;
- limit testing to what is necessary to identify and demonstrate a vulnerability;
- stop and report immediately if you encounter personal data, Customer Data, credentials, secrets, or another person’s confidential information;
- avoid copying, downloading, changing, deleting, retaining, or disclosing data beyond the minimum evidence needed;
- avoid persistence, lateral movement, privilege expansion, and access to additional accounts after confirming the issue;
- avoid degrading performance or availability;
- protect vulnerability details and any inadvertently accessed information from disclosure; and
- give Blossom a reasonable opportunity to investigate and remediate before any public disclosure.
Delete any data obtained through testing as soon as Blossom confirms it is no longer needed for validation, and in all cases when Blossom asks unless law requires preservation.
3. Prohibited testing
In short: Do not use social engineering, denial of service, physical attacks, malicious code, mass automation, or attacks on people and vendors.
The following are not authorized:
- denial-of-service, load, stress, or resource-exhaustion testing;
- destructive testing, ransomware, malware, cryptomining, or persistent payloads;
- phishing, pretexting, social engineering, spam, or testing employees, contractors, customers, or support channels;
- physical intrusion, device theft, or testing offices and facilities;
- credential stuffing, password spraying, brute force, or use of breached credentials;
- automated scanning at a volume that could affect reliability or generate excessive traffic;
- accessing, altering, deleting, exfiltrating, or publicly exposing Customer Data or personal data;
- testing third-party vendors, Customer-Connected Services, or customer systems without their separate authorization;
- financial fraud, payment testing with unauthorized instruments, or attempts to move funds; and
- extortion, threats, or conditioning nondisclosure on payment.
Reports limited to missing security headers, unverified scanner output, self-XSS, clickjacking without sensitive impact, rate limits with no demonstrated risk, or outdated software without an exploitable condition may be closed as informational.
4. How to report
In short: Email a clear, reproducible report to legal@blossom.fm and do not include unnecessary sensitive data.
Send reports to legal@blossom.fm with the subject “Security Vulnerability Report.” Include:
- the affected URL, endpoint, feature, and account type;
- a concise description of the vulnerability and likely impact;
- reproducible steps or a minimal proof of concept;
- relevant request identifiers, timestamps, screenshots, or sanitized logs;
- whether you encountered or retained any data; and
- your preferred contact details and disclosure timeline.
Do not send active malware, full credential sets, unnecessary personal data, or large raw datasets. Ask before sending an attachment that may be unsafe or sensitive. Encrypted-reporting instructions may be arranged through the contact address.
5. What Blossom will do
In short: Blossom will acknowledge, triage, communicate, and work toward remediation based on severity.
Blossom intends to acknowledge a complete report within five business days, provide an initial triage response within ten business days, and share material status updates as the investigation progresses. These are targets, not service-level commitments. Timing depends on severity, complexity, dependencies, and whether we can reproduce the issue.
We may ask for clarification, coordinate validation, or request that testing stop. We will not require a researcher to waive good-faith legal rights as a condition of receiving an update. Blossom does not currently operate a bug-bounty program and does not promise payment, gifts, public credit, or other compensation.
6. Safe harbor
In short: If you follow this policy in good faith, Blossom will treat the research as authorized and will not pursue legal action over it.
If Blossom concludes that your research complied with this policy in good faith, Blossom will:
- consider that research authorized under the Computer Fraud and Abuse Act and similar state laws, and not initiate or support legal action against you for accidental, good-faith violations;
- not bring a Digital Millennium Copyright Act claim for circumvention undertaken solely to perform the authorized research; and
- work with you to understand and resolve any uncertainty about whether conduct is permitted.
This safe harbor binds only Blossom. It does not authorize activity against a third party or prevent a third party, regulator, or government from taking action. Blossom cannot authorize violations of law. If a third party initiates action based solely on policy-compliant research against Blossom, we will state that the research was conducted under this policy where we are legally permitted to do so.
If you are uncertain, contact us before continuing. We prefer to clarify scope over receiving a report after avoidable harm.
7. Coordinated disclosure
In short: Please coordinate publication so users can be protected before technical details become public.
Do not publicly disclose a vulnerability or Customer information until Blossom confirms remediation or the parties agree on a disclosure date. We will consider severity, active exploitation, customer protections, vendor dependencies, and the public interest in proposing a timeline. If we cannot agree, give us reasonable advance notice before disclosure and continue to protect personal data, credentials, and exploit details that would create avoidable harm.
8. Changes and contact
In short: We may update this policy prospectively; questions go to legal@blossom.fm.
Material changes will receive at least 30 days’ advance notice on this page unless a faster update is needed to protect security or comply with law. Changes do not retroactively remove safe harbor from research that complied with the version in effect when performed.
Contact: Noah Lenz, legal@blossom.fm.
Changelog
In short: This is the first working-draft version.
| Date | Version | Change |
|---|---|---|
| July 22, 2026 | 0.1 | Initial working draft for counsel review. |