Security

Reporting a vulnerability

VibeLock operates a coordinated disclosure programme. This page sets out what is in scope, the commitments we make on response times, and the conditions under which testing is authorised.

Scope

In scope
  • vibelock.ai and every subdomain
  • The VibeLock API
  • The agent package on npm
  • Authentication and session handling
  • Data isolation between accounts
  • Trust page access controls
Out of scope
  • Supabase infrastructureReport to Supabase
  • Railway hostingReport to Railway
  • Stripe payment processingReport to Stripe
  • Resend email deliveryReport to Resend
  • The Anthropic APIReport to Anthropic
  • Social engineering of peopleNever in scope
  • Denial of serviceNever in scope
  • Automated scanning without coordinationCoordinate first

What you get back

24 hours
Receipt acknowledged.
5 days
Triage complete and initial severity assessment issued.
30 days
Critical and high severity issues resolved.
90 days
Medium and low severity issues resolved.

What to include

  • The vulnerability and its potential impact
  • Step by step reproduction
  • Proof of concept: screenshots, a recording, or code
  • Your assessment of severity and exploitability
  • Any proposed remediation, if available

Rules of engagement

  • Do not access another account or another person’s data
  • Do not run denial of service tests
  • Do not social engineer anyone connected to VibeLock
  • Do not run automated scanners without coordinating first
  • Do not disclose publicly before we have had time to fix it
Send it

Email security@vibelock.ai. Acknowledged within 24 hours. We do not currently pay bounties, and we say so here rather than letting you find out after the work.