Security Policy

Effective date: August 2, 2026
Last updated: August 2, 2026

LaborCode.ph values the security of its website, visitors and data. This public Security and Responsible Disclosure Policy explains how to report a suspected vulnerability and what testing is permitted.

1. Scope

This Policy applies to publicly accessible systems and pages under the LaborCode.ph domain that are operated by LaborCode.ph. It does not authorize testing of hosting providers, content-delivery networks, analytics services, government websites, external links, social-media accounts or other third-party systems.

2. Reporting a security concern

Report a suspected vulnerability through the Privacy or Security Concern contact route. Include the affected URL or component, a clear description, potential impact, safe reproduction steps, relevant screenshots or logs, and a way to contact you. Do not include personal data, credentials, malware or confidential third-party information unless specifically requested through a secure channel.

3. Good-faith research

We intend to treat research as good-faith and authorized for purposes of our response when it is limited to the in-scope website, follows this Policy, avoids harm, uses the minimum testing necessary to confirm the issue, stops after confirmation and reports the issue promptly and privately.

This statement applies only to systems we control and does not bind third parties, service providers, regulators or law-enforcement authorities. It does not authorize conduct prohibited by law.

4. Permitted testing

Permitted activity is limited to passive review and low-impact testing reasonably necessary to demonstrate a vulnerability. Use your own account or data where applicable. Minimize requests, avoid persistence, and stop immediately if you encounter personal data, credentials, confidential information, service instability or access beyond what was intended.

5. Prohibited activity

Do not conduct denial-of-service or load testing; automated scanning that materially affects performance; social engineering, phishing or impersonation; physical attacks; malware deployment; credential stuffing; password spraying; brute force; spam; data destruction or alteration; privilege escalation beyond minimal confirmation; persistence; lateral movement; access to another person’s data; public disclosure before remediation; extortion; or testing of third-party services.

Do not download, copy, retain, transmit or disclose personal data or confidential information. If such information is encountered, stop, do not access more, describe the exposure without including the data and delete any local copies after coordinating with us.

6. What to expect after a report

We will review credible reports and may request clarification, validate the issue, prioritize remediation based on risk and provide updates when practical. Response and remediation times vary with severity, complexity, third-party dependencies and available resources.

Please keep the report confidential until we confirm that remediation is complete or agree on a disclosure plan. We may not respond to spam, vague automated reports, issues outside scope, reports without security impact or submissions that violate this Policy.

7. Recognition and rewards

LaborCode.ph does not currently operate a public bug-bounty program and does not promise payment, gifts or public recognition. Any reward or acknowledgment must be agreed in writing before it is considered binding.

8. Security practices

LaborCode.ph uses administrative, technical and organizational measures intended to reduce risk, including access controls, software maintenance, security monitoring, backups and service-provider safeguards appropriate to the website. No system can be guaranteed completely secure.

9. Personal-data incidents

A suspected exposure of personal data should be reported immediately through the same security contact route. LaborCode.ph will assess whether notification to affected individuals or the National Privacy Commission is required under applicable Philippine data-protection rules.

10. Legal compliance

Unauthorized access, interference, data misuse and related conduct may be prohibited by Philippine law, including the Data Privacy Act of 2012 and the Cybercrime Prevention Act of 2012. This Policy does not grant permission beyond its express scope.

11. Changes to this Policy

We may update this Policy as systems, providers, risks or legal requirements change. The latest version and last-updated date will appear on this page.

12. Official references

For general data-breach information, see the National Privacy Commission breach-reporting guidance. The Cybercrime Prevention Act of 2012 is available through the Lawphil Project.

See also: Privacy Policy · Terms of Service · Cookies Policy · Legal Disclaimer.