Skip to main content
戻る
Security & Coordinated Disclosure

Security & Coordinated Disclosure

最終更新: April 23, 2026

英語版のみ提供

この文書は英語でのみ公開されています。内容に不明な点がある場合は、サービスをご利用になる前にお問い合わせください: legal@signalfloor.com

1. How to report a vulnerability

Email security@signalfloor.com with a clear description of the issue. A proof-of-concept is welcomed but not required. Machine-readable contact is also published at /.well-known/security.txt per RFC 9116.

We respond within 3 business days. Reports that look credible move to a private tracking ticket within 24 hours.

2. Scope

In scope:

  • signalfloor.com and its subdomains (except third-party subdomains we don't own).
  • The SignalFloor native app on Android and iOS.
  • Supabase-hosted edge functions under vszujmlwpywubgzfrxbs.supabase.co.
  • Authentication, payment, and API surfaces — vulnerabilities that could affect user data or money movement are highest priority.

Out of scope:

  • Automated scanner findings without a concrete impact (e.g. “missing X-Frame-Options header” on a static marketing page).
  • Denial-of-service attacks against production, or rate-limit bypass reports that require volumes that themselves constitute an attack.
  • Social-engineering attacks on SignalFloor staff or contractors.
  • Issues on third-party integrations (Resend, Stripe, Firebase) — report those directly to the vendor.
  • Self-XSS and “log-in with your own account” findings that don't affect other users.

3. Safe harbor for good-faith research

We will not take legal action against security researchers who follow this policy in good faith. Specifically, we commit to not pursuing claims under the Computer Fraud and Abuse Act or equivalent non-US laws if you:

  • Avoid privacy violations, data destruction, and service interruption.
  • Only interact with accounts you own or have explicit permission to test.
  • Report promptly and give us reasonable time to fix before publishing.
  • Don't exfiltrate data beyond the minimum needed to demonstrate the issue.

4. Disclosure timeline

We aim to fix and deploy within 30 days of a confirmed high- or critical-severity report; up to 90 days for medium; up to 180 for low. We'll credit you in a post-fix disclosure if you want, or keep the report private if you prefer.

If we can't ship a fix in the committed window (rare, but it happens when a vendor patch is blocking), we'll tell you before the deadline and agree on an extension. We don't leave researchers guessing.

5. Bounties

We don't run a standing bug-bounty program yet, but we do discretionary awards for high-impact reports. The baseline is a public credit + SignalFloor-branded swag; anything exploitable against production payments or user accounts tends to unlock a cash reward we negotiate at the time of the fix. If bounty economics matter to you, we prefer you say so up front so nobody feels misled.

6. PGP / encrypted report

If your report includes sensitive customer data or an exploitable chain, reply to the initial ack from security@signalfloor.com and we'll share a one-time encrypted channel (Signal, ProtonMail, or a Keybase room). We don't publish a standing PGP key — rotating them is operationally painful and on-demand sharing has worked better for the reports we've received.

SignalFloor

SignalFloor – トレーディングクリエイター基盤。検証済みチャネル、コース、ライブルームと決済済みトレード履歴。

クリエイターハブ

  • マーケット
  • ·リーダーボード
  • ·シグナル
  • ·専門別
  • ·為替クリエイター
  • ·暗号資産クリエイター
  • ·株式クリエイター
  • ·指数クリエイター
  • ·商品クリエイター
  • ·ベスト一覧
  • ·最良の為替
  • ·最良の暗号資産
  • ·最良の検証済み
  • ·EUR/USDシグナル
  • ·GBP/USDシグナル
  • ·BTC/USDシグナル
  • ·XAU/USDシグナル
  • ·PPSの計算式
  • ·Creator Fit
  • ·ティアの計算式
  • ·比較
  • ·用語集
  • ·はじめに
  • ·Signal Engine のルール
  • ·ステータス
  • ·リリース
  • ·ブランド
  • ·APIドキュメント
  • ·トレードジャーナル

ナビゲーション

機能 チャンネル クリエイター ランキング Courses Learn Live 料金 クリエイター向け スタートガイド 概要

リソース

使い方 PPS の算出方法 トレーディングシグナルとは? SignalFloorは信頼できる? ブログ すべてのガイド トレーディング計算機 アプリをダウンロード

法的情報

お問い合わせ 利用規約 プライバシー リスク開示 返金ポリシー
言語

© 2026 SignalFloor. 全著作権所有。

v1.7.0