Please include as much detail as possible to help us understand and reproduce the issue.
What to Include in Your Report
A clear description of the vulnerability
Steps to reproduce the issue
Potential impact of the vulnerability
Any proof-of-concept code or screenshots
Your contact information for follow-up
Response Time
24 hours
Initial acknowledgment of your report
72 hours
Initial assessment and triage
14 days
Target for remediation (may vary based on severity and complexity)
Safe Harbor
We will not pursue legal action against researchers who report vulnerabilities in good faith and follow responsible disclosure practices.
✓Make good faith efforts to avoid privacy violations and data destruction
✓Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
✓Give us reasonable time to address the issue before public disclosure
✓Do not access or modify data belonging to other users
Out of Scope
The following are generally considered out of scope:
• Denial of service attacks
• Social engineering attacks against our employees
• Physical attacks against our infrastructure
• Issues in third-party applications or services we use
• Spam or social engineering techniques
• Missing security headers that don't lead to exploitable vulnerabilities
• Rate limiting or brute force issues on non-authentication endpoints
Bug Bounty Program
We do not currently offer a formal bug bounty program with monetary rewards. However, we deeply appreciate responsible disclosure and will acknowledge researchers who help us improve our security (with permission).
A formal bug bounty program may be considered in the future as the company grows.