Skip to content

Security

Responsible disclosure

Found a security problem in VibeBeacon? Tell us before you tell anyone else, and we will fix it.

Email security@vibebeacon.app with what you found, the steps to reproduce it and, if you have one, a proof of concept. We read every report and reply to let you know we have received it. A machine-readable version of this contact is at /.well-known/security.txt.

1

What to report

  • Any way to read, change or delete another account's apps, alerts or data.
  • Any way around sign-in, API key checks or rate limits.
  • Any way to run code on our servers, or to make us leak secrets or credentials.
  • Cross-site scripting, injection, or a broken access control on any route.

2

What we ask

  • Give us a reasonable amount of time to fix the issue before telling anyone else.
  • Do not access, change or delete data that is not yours while testing.
  • Do not run automated scanners that could degrade the service for other users.
  • Do not use social engineering against our staff or users.

3

What we store

We hold package names, versions and a small amount of account data, nothing else. The full, field-by-field description is on the privacy page.

4

What you can expect

We do not run a paid bug bounty at this stage. We will credit you by name (if you want that) once a fix ships, and we will not pursue legal action against anyone who reports in good faith and follows the guidelines above. Questions about anything else: email hello@vibebeacon.app.

Security | VibeBeacon