Back
Security & Coordinated Disclosure

Security & Coordinated Disclosure

Last updated: April 23, 2026

1. How to report a vulnerability

Email security@signalfloor.com with a clear description of the issue. A proof-of-concept is welcomed but not required. Machine-readable contact is also published at /.well-known/security.txt per RFC 9116.

We respond within 3 business days. Reports that look credible move to a private tracking ticket within 24 hours.

2. Scope

In scope:

  • signalfloor.com and its subdomains (except third-party subdomains we don't own).
  • The SignalFloor native app on Android and iOS.
  • Supabase-hosted edge functions under vszujmlwpywubgzfrxbs.supabase.co.
  • Authentication, payment, and API surfaces — vulnerabilities that could affect user data or money movement are highest priority.

Out of scope:

  • Automated scanner findings without a concrete impact (e.g. “missing X-Frame-Options header” on a static marketing page).
  • Denial-of-service attacks against production, or rate-limit bypass reports that require volumes that themselves constitute an attack.
  • Social-engineering attacks on SignalFloor staff or contractors.
  • Issues on third-party integrations (Resend, Stripe, Firebase) — report those directly to the vendor.
  • Self-XSS and “log-in with your own account” findings that don't affect other users.

3. Safe harbor for good-faith research

We will not take legal action against security researchers who follow this policy in good faith. Specifically, we commit to not pursuing claims under the Computer Fraud and Abuse Act or equivalent non-US laws if you:

  • Avoid privacy violations, data destruction, and service interruption.
  • Only interact with accounts you own or have explicit permission to test.
  • Report promptly and give us reasonable time to fix before publishing.
  • Don't exfiltrate data beyond the minimum needed to demonstrate the issue.

4. Disclosure timeline

We aim to fix and deploy within 30 days of a confirmed high- or critical-severity report; up to 90 days for medium; up to 180 for low. We'll credit you in a post-fix disclosure if you want, or keep the report private if you prefer.

If we can't ship a fix in the committed window (rare, but it happens when a vendor patch is blocking), we'll tell you before the deadline and agree on an extension. We don't leave researchers guessing.

5. Bounties

We don't run a standing bug-bounty program yet, but we do discretionary awards for high-impact reports. The baseline is a public credit + SignalFloor-branded swag; anything exploitable against production payments or user accounts tends to unlock a cash reward we negotiate at the time of the fix. If bounty economics matter to you, we prefer you say so up front so nobody feels misled.

6. PGP / encrypted report

If your report includes sensitive customer data or an exploitable chain, reply to the initial ack from security@signalfloor.com and we'll share a one-time encrypted channel (Signal, ProtonMail, or a Keybase room). We don't publish a standing PGP key — rotating them is operationally painful and on-demand sharing has worked better for the reports we've received.