Reporting a vulnerability
VibeLock operates a coordinated disclosure programme. This page sets out what is in scope, the commitments we make on response times, and the conditions under which testing is authorised.
Scope
In scope
- vibelock.ai and every subdomain
- The VibeLock API
- The agent package on npm
- Authentication and session handling
- Data isolation between accounts
- Trust page access controls
Out of scope
- Supabase infrastructureReport to Supabase
- Railway hostingReport to Railway
- Stripe payment processingReport to Stripe
- Resend email deliveryReport to Resend
- The Anthropic APIReport to Anthropic
- Social engineering of peopleNever in scope
- Denial of serviceNever in scope
- Automated scanning without coordinationCoordinate first
What you get back
- 24 hours
- Receipt acknowledged.
- 5 days
- Triage complete and initial severity assessment issued.
- 30 days
- Critical and high severity issues resolved.
- 90 days
- Medium and low severity issues resolved.
What to include
- The vulnerability and its potential impact
- Step by step reproduction
- Proof of concept: screenshots, a recording, or code
- Your assessment of severity and exploitability
- Any proposed remediation, if available
Rules of engagement
- Do not access another account or another person’s data
- Do not run denial of service tests
- Do not social engineer anyone connected to VibeLock
- Do not run automated scanners without coordinating first
- Do not disclose publicly before we have had time to fix it
Email security@vibelock.ai. Acknowledged within 24 hours. We do not currently pay bounties, and we say so here rather than letting you find out after the work.