Back to Trust Center

Vulnerability Disclosure

Version: v1.0 | Last Updated: January 2026

Vulnerability Disclosure Policy

We appreciate the security research community's efforts to help keep SimplyPNG secure.

How to Report

Please send vulnerability reports to:

security@simplypng.app

Please include as much detail as possible to help us understand and reproduce the issue.

What to Include in Your Report

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any proof-of-concept code or screenshots
  • Your contact information for follow-up

Response Time

24 hours
Initial acknowledgment of your report
72 hours
Initial assessment and triage
14 days
Target for remediation (may vary based on severity and complexity)

Safe Harbor

We will not pursue legal action against researchers who report vulnerabilities in good faith and follow responsible disclosure practices.

  • Make good faith efforts to avoid privacy violations and data destruction
  • Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
  • Give us reasonable time to address the issue before public disclosure
  • Do not access or modify data belonging to other users

Out of Scope

The following are generally considered out of scope:

  • • Denial of service attacks
  • • Social engineering attacks against our employees
  • • Physical attacks against our infrastructure
  • • Issues in third-party applications or services we use
  • • Spam or social engineering techniques
  • • Missing security headers that don't lead to exploitable vulnerabilities
  • • Rate limiting or brute force issues on non-authentication endpoints

Bug Bounty Program

We do not currently offer a formal bug bounty program with monetary rewards. However, we deeply appreciate responsible disclosure and will acknowledge researchers who help us improve our security (with permission).

A formal bug bounty program may be considered in the future as the company grows.

Questions about this policy? Contact our security team