Security
Responsible disclosure
Found a security problem in VibeBeacon? Tell us before you tell anyone else, and we will fix it.
Email security@vibebeacon.app with what you found, the steps to reproduce it and, if you have one, a proof of concept. We read every report and reply to let you know we have received it. A machine-readable version of this contact is at /.well-known/security.txt.
1
What to report
- Any way to read, change or delete another account's apps, alerts or data.
- Any way around sign-in, API key checks or rate limits.
- Any way to run code on our servers, or to make us leak secrets or credentials.
- Cross-site scripting, injection, or a broken access control on any route.
2
What we ask
- Give us a reasonable amount of time to fix the issue before telling anyone else.
- Do not access, change or delete data that is not yours while testing.
- Do not run automated scanners that could degrade the service for other users.
- Do not use social engineering against our staff or users.
3
What we store
We hold package names, versions and a small amount of account data, nothing else. The full, field-by-field description is on the privacy page.
4
What you can expect
We do not run a paid bug bounty at this stage. We will credit you by name (if you want that) once a fix ships, and we will not pursue legal action against anyone who reports in good faith and follows the guidelines above. Questions about anything else: email hello@vibebeacon.app.