Skip to main content
뒤로
Security & Coordinated Disclosure

Security & Coordinated Disclosure

최종 업데이트: April 23, 2026

영어로만 제공

이 문서는 영어로만 게시되어 있습니다. 이해되지 않는 부분이 있으면 서비스를 이용하기 전에 문의해 주세요: legal@signalfloor.com

1. How to report a vulnerability

Email security@signalfloor.com with a clear description of the issue. A proof-of-concept is welcomed but not required. Machine-readable contact is also published at /.well-known/security.txt per RFC 9116.

We respond within 3 business days. Reports that look credible move to a private tracking ticket within 24 hours.

2. Scope

In scope:

  • signalfloor.com and its subdomains (except third-party subdomains we don't own).
  • The SignalFloor native app on Android and iOS.
  • Supabase-hosted edge functions under vszujmlwpywubgzfrxbs.supabase.co.
  • Authentication, payment, and API surfaces — vulnerabilities that could affect user data or money movement are highest priority.

Out of scope:

  • Automated scanner findings without a concrete impact (e.g. “missing X-Frame-Options header” on a static marketing page).
  • Denial-of-service attacks against production, or rate-limit bypass reports that require volumes that themselves constitute an attack.
  • Social-engineering attacks on SignalFloor staff or contractors.
  • Issues on third-party integrations (Resend, Stripe, Firebase) — report those directly to the vendor.
  • Self-XSS and “log-in with your own account” findings that don't affect other users.

3. Safe harbor for good-faith research

We will not take legal action against security researchers who follow this policy in good faith. Specifically, we commit to not pursuing claims under the Computer Fraud and Abuse Act or equivalent non-US laws if you:

  • Avoid privacy violations, data destruction, and service interruption.
  • Only interact with accounts you own or have explicit permission to test.
  • Report promptly and give us reasonable time to fix before publishing.
  • Don't exfiltrate data beyond the minimum needed to demonstrate the issue.

4. Disclosure timeline

We aim to fix and deploy within 30 days of a confirmed high- or critical-severity report; up to 90 days for medium; up to 180 for low. We'll credit you in a post-fix disclosure if you want, or keep the report private if you prefer.

If we can't ship a fix in the committed window (rare, but it happens when a vendor patch is blocking), we'll tell you before the deadline and agree on an extension. We don't leave researchers guessing.

5. Bounties

We don't run a standing bug-bounty program yet, but we do discretionary awards for high-impact reports. The baseline is a public credit + SignalFloor-branded swag; anything exploitable against production payments or user accounts tends to unlock a cash reward we negotiate at the time of the fix. If bounty economics matter to you, we prefer you say so up front so nobody feels misled.

6. PGP / encrypted report

If your report includes sensitive customer data or an exploitable chain, reply to the initial ack from security@signalfloor.com and we'll share a one-time encrypted channel (Signal, ProtonMail, or a Keybase room). We don't publish a standing PGP key — rotating them is operationally painful and on-demand sharing has worked better for the reports we've received.

SignalFloor

SignalFloor – 트레이딩 크리에이터 플랫폼. 검증된 채널, 코스, 라이브 룸과 전체 청산 거래 기록.

크리에이터 허브

  • 마켓플레이스
  • ·리더보드
  • ·시그널
  • ·전문 분야별
  • ·외환 크리에이터
  • ·크립토 크리에이터
  • ·주식 크리에이터
  • ·지수 크리에이터
  • ·원자재 크리에이터
  • ·베스트 목록
  • ·베스트 외환
  • ·베스트 크립토
  • ·베스트 검증
  • ·EUR/USD 시그널
  • ·GBP/USD 시그널
  • ·BTC/USD 시그널
  • ·XAU/USD 시그널
  • ·PPS 공식
  • ·Creator Fit
  • ·티어 공식
  • ·비교
  • ·용어집
  • ·시작하기
  • ·Signal Engine 규칙
  • ·상태
  • ·릴리스
  • ·브랜드
  • ·API 문서
  • ·트레이드 저널

탐색

기능 채널 크리에이터 리더보드 Courses Learn Live 가격 크리에이터 안내 시작 가이드 소개

리소스

이용 방법 PPS 공식 트레이딩 시그널이란? SignalFloor은 신뢰할 수 있나요? 블로그 모든 가이드 거래 계산기 앱 다운로드

법적 정보

연락처 약관 개인정보 위험 공시 환불 정책
언어

© 2026 SignalFloor. 모든 권리 보유.

v1.7.0