Devtegra.

Security Vulnerability Disclosure Policy

Effective Date: June 20, 2026 Last Updated: July 29, 2026

Devtegra, LLC (“Devtegra,” “we,” “us,” or “our”) welcomes reports from security researchers and members of the public who discover potential vulnerabilities in our products, including the FitCreature mobile app and its backend services. This policy explains what is in scope, how to report a problem, what we ask of you, and the limited authorization we extend to good-faith research. Please read it in full before you begin. By submitting a report or conducting research on our systems, you agree to this policy.

How to report

Email security@devtegra.com with a description of the issue. Where you can, please include:

You do not need an account or prior permission to report. If you would prefer to send an encrypted message, say so in a first plain message and we will arrange a channel.

What we ask of you

To stay within this policy, you must:

If you do not meet these conditions, the authorization and safe harbor below do not apply to your activity.

Authorization and safe harbor

If you make a good-faith effort to follow this policy, Devtegra will:

This authorization is limited. It applies only to the systems listed under Scope, only while you act in good faith, and only to claims that Devtegra itself can bring or control. Devtegra may suspend or revoke this authorization at any time. The safe harbor does not:

Devtegra will make a good-faith determination of whether your conduct met the conditions of this policy. Nothing in this policy limits Devtegra’s rights or remedies with respect to conduct that falls outside it, and Devtegra reserves all of those rights.

Scope

In scope:

Out of scope:

If you are unsure whether something is in scope, ask us before you test it.

How we handle your report

We do not currently run a paid bug bounty program. Reports are handled on a goodwill basis, and you should not expect payment. This may change in the future, and if we introduce paid rewards we will publish separate terms.

Eligibility

To participate, you must have the legal capacity to agree to this policy, and you must comply with all applicable export-control and sanctions laws. You represent that you are not located in an embargoed jurisdiction and are not on any government sanctions or denied-party list.

Your other obligations as a user

Our Terms of Service continue to apply to your use of the Services while you research, including the disclaimers, the limitation of liability, and the indemnification provisions, except where the authorization and safe harbor above expressly apply. This policy creates no contract, employment, agency, or partnership relationship between you and Devtegra.

No warranty

The Services are provided “as is” for purposes of your research. Devtegra makes no warranty in connection with this policy or your participation, and the timelines stated here are goals rather than binding commitments.

Governing law

This policy, and any dispute relating to your participation in it, is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles. The exclusive venue for any such dispute is the state and federal courts located in Travis County, Texas, and you consent to the personal jurisdiction of those courts. Devtegra may seek injunctive relief in any court of competent jurisdiction.

Changes to this policy

We may update this policy at any time. The version published on this page at devtegra.com/security is the authoritative version. Your continued participation after we post changes means you accept them.

Devtegra, LLC Texas, United States