Balosys

Responsible Disclosure

Security vulnerability reporting for the Balosys platform

Literary Worx LLC · Effective June 2026 · info@literaryworx.com

Literary Worx LLC takes the security of the Balosys platform seriously. We welcome good-faith security research and responsible disclosure of vulnerabilities. This Policy describes how to report security issues and what researchers can expect from us.

1. Scope

This Policy applies to security vulnerabilities discovered in:

  • The Balosys web platform at balosys.com
  • The Balosys API and AI query infrastructure
  • User authentication and account management systems
  • Subscriber data and session management
  • Literary Worx LLC owned infrastructure (literaryworx.com)

This Policy does not cover third-party platforms (Anthropic, Webflow, HeyGen), subscriber systems or devices, or social engineering attempts.

2. How to Report

Report vulnerabilities promptly and confidentially:

  • Email: info@literaryworx.com
  • Subject line: [SECURITY] Responsible Disclosure

Please include:

  • Description of the vulnerability and potential impact
  • Step-by-step reproduction instructions
  • Platform component or URL affected
  • Proof-of-concept without accessing live user data
  • Your contact information for follow-up

3. Our Commitments to Researchers

  • Acknowledgment within 3 business days
  • Good-faith investigation of all reported vulnerabilities
  • Assessment and remediation timeline within 14 business days
  • Notification when the vulnerability has been remediated
  • Recognition of your contribution (with permission) upon resolution
  • No legal action against researchers acting in good faith under this Policy

4. Safe Harbor

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, refrain from accessing data beyond what is necessary to demonstrate the issue, do not exploit vulnerabilities for other purposes, allow reasonable remediation time before public disclosure, and do not conduct denial-of-service attacks or access subscriber PII.

5. Coordinated Disclosure

We request a minimum of ninety (90) calendar days from acknowledgment before public disclosure. For imminent risks, contact info@literaryworx.com immediately for coordinated response.

6. Out-of-Scope Activities

  • Accessing, modifying, or deleting subscriber data or PII
  • Denial-of-service attacks or service disruption
  • Physical security testing
  • Social engineering of personnel or subscribers
  • Automated scanners that impact platform performance

7. Modifications

We may update this Policy at any time. Changes are effective upon posting at balosys.com. Questions: info@literaryworx.com.

← Back to platform