Trust

Security at IntBooks

Last updated:

Our security posture

Responsible-disclosure programme

We thank security researchers who help us keep IntBooks safe. If you believe you have found a vulnerability, email security@intbooks.my with:

We will acknowledge receipt within 2 business days and provide a triage decision within 10 business days. Do not publicly disclose the issue until we have shipped a fix or 90 days have passed, whichever comes first.

In scope

Out of scope

Bounty & rewards

We do not yet operate a paid bounty programme. Eligible reporters of previously-unknown, in-scope vulnerabilities receive public credit (with consent) and IntBooks swag. Critical vulnerabilities ranked CVSS 9.0+ are eligible for a goodwill RM 1,500 reward at our discretion until a formal programme launches.

Acknowledgments

We are grateful to the researchers who have responsibly disclosed issues. Names are listed here with consent.

Status & incidents

Live system status, post-mortems, and historical uptime are published on our incident page (linked from the in-app footer during outages). Subscribe via your account preferences to receive incident notifications.