Security Policy

We take the security of our systems seriously. If you believe you have found a security vulnerability in our application, please report it to us as described below.

Reporting a Vulnerability

Please email your findings to [email protected]. Do not report security vulnerabilities through public GitHub issues, social media, or customer support channels.

Please include the following in your report:

  • Description of the vulnerability and its potential impact.
  • Detailed steps to reproduce the issue (including any proof-of-concept scripts or screenshots).
  • Your contact information.

We will acknowledge receipt of your vulnerability report within 3 business days and strive to send you regular updates about our progress.

Out of Scope

The following activities are strictly prohibited and fall outside our safe harbor policy:

  • Volumetric attacks (DoS/DDoS).
  • Social engineering or phishing of our employees or contractors.
  • Physical attacks against our facilities or infrastructure.
  • Submitting output strictly from automated vulnerability scanners.
  • Interacting with accounts or data that do not belong to you.

Reward Policy

We currently do not offer financial compensation or a bug bounty program for vulnerability reports.