Security Policy
We take the security of our systems seriously. If you believe you have found a security vulnerability in our application, please report it to us as described below.
Reporting a Vulnerability
Please email your findings to [email protected]. Do not report security vulnerabilities through public GitHub issues, social media, or customer support channels.
Please include the following in your report:
- Description of the vulnerability and its potential impact.
- Detailed steps to reproduce the issue (including any proof-of-concept scripts or screenshots).
- Your contact information.
We will acknowledge receipt of your vulnerability report within 3 business days and strive to send you regular updates about our progress.
Out of Scope
The following activities are strictly prohibited and fall outside our safe harbor policy:
- Volumetric attacks (DoS/DDoS).
- Social engineering or phishing of our employees or contractors.
- Physical attacks against our facilities or infrastructure.
- Submitting output strictly from automated vulnerability scanners.
- Interacting with accounts or data that do not belong to you.
Reward Policy
We currently do not offer financial compensation or a bug bounty program for vulnerability reports.