Vulnerability disclosure policy

Last updated: October 2026

Venues and their visitors rely on Beyonk to keep bookings, payments and personal data safe. If you think you have found a security vulnerability in our platform or website, we want to hear from you.

This page explains what is in scope, how to report an issue and what you can expect from us.

For anything that isn't a security vulnerability, such as help with your account or a booking, please contact support@beyonk.com.

Scope

In scope:

  • beyonk.com and its subdomains
  • Beyonk booking, checkout and ticketing pages
  • The Beyonk dashboard used by our customers

Out of scope:

  • Third-party services we use but do not run, such as payment providers. Please report those to the provider directly.
  • Denial of service, spam or volume-based testing
  • Social engineering, phishing or physical attacks against Beyonk staff, customers or offices
  • Reports from automated scanners without a working proof of concept
  • Missing best-practice settings with no clear security impact

    Testing guidelines

    When testing, please:

    • Only use accounts you own or have permission to use
    • Avoid accessing, changing or deleting data that isn't yours. If you come across personal data, stop and tell us in your report.
    • Avoid anything that could disrupt our service or our customers' events
    • Give us a reasonable time to fix the issue before sharing it publicly [90 days]

      Safe harbour

      If you make a good-faith effort to follow this policy, we will consider your research authorised and will not take legal action against you for it. If a third party takes action against you for activity that followed this policy, we will make it known that your actions were authorised.

      Your journey to easier and more powerful ticket sales starts here

      Quick sign-up, no obligations