← Back to Security

Vulnerability Disclosure

Report Security Issues

[email protected]

What Can Be Tested

  • Authentication and session management vulnerabilities
  • Authorization bypass and capability escalation
  • Cross-tenant access attempts
  • Injection attacks (SQL, command, etc.)
  • XSS, CSRF, and logic flaws
  • Access control bypasses
  • Cryptographic weaknesses

What NOT to Test

  • Denial of Service or performance testing
  • Accessing other users' accounts
  • Physical security or social engineering
  • Testing third-party systems (GitHub, AWS, etc.)
  • Automated scanning without permission

Report Requirements

Include:

  • Vulnerability title and description
  • Severity estimate (Critical/High/Medium/Low)
  • Affected component and versions
  • Step-by-step reproduction instructions
  • Proof of concept (code, script, screenshot)
  • Impact analysis
  • Your contact information

Our Commitment

  • Acknowledge receipt within 24 hours
  • Triage and classify within 48 hours
  • Fix timeline based on severity
  • Public credit upon disclosure
  • Safe harbor for good-faith researchers

Full Policy

See docs/legal/VULNERABILITY_DISCLOSURE_POLICY.md for complete disclosure policy, scope, and coordinated disclosure details.