Skip to main content
返回
Security & Coordinated Disclosure

Security & Coordinated Disclosure

最后更新:April 23, 2026

仅提供英文版本

本文件仅以英文发布。如有任何内容不清楚,请在使用本服务前咨询: legal@signalfloor.com

1. How to report a vulnerability

Email security@signalfloor.com with a clear description of the issue. A proof-of-concept is welcomed but not required. Machine-readable contact is also published at /.well-known/security.txt per RFC 9116.

We respond within 3 business days. Reports that look credible move to a private tracking ticket within 24 hours.

2. Scope

In scope:

  • signalfloor.com and its subdomains (except third-party subdomains we don't own).
  • The SignalFloor native app on Android and iOS.
  • Supabase-hosted edge functions under vszujmlwpywubgzfrxbs.supabase.co.
  • Authentication, payment, and API surfaces — vulnerabilities that could affect user data or money movement are highest priority.

Out of scope:

  • Automated scanner findings without a concrete impact (e.g. “missing X-Frame-Options header” on a static marketing page).
  • Denial-of-service attacks against production, or rate-limit bypass reports that require volumes that themselves constitute an attack.
  • Social-engineering attacks on SignalFloor staff or contractors.
  • Issues on third-party integrations (Resend, Stripe, Firebase) — report those directly to the vendor.
  • Self-XSS and “log-in with your own account” findings that don't affect other users.

3. Safe harbor for good-faith research

We will not take legal action against security researchers who follow this policy in good faith. Specifically, we commit to not pursuing claims under the Computer Fraud and Abuse Act or equivalent non-US laws if you:

  • Avoid privacy violations, data destruction, and service interruption.
  • Only interact with accounts you own or have explicit permission to test.
  • Report promptly and give us reasonable time to fix before publishing.
  • Don't exfiltrate data beyond the minimum needed to demonstrate the issue.

4. Disclosure timeline

We aim to fix and deploy within 30 days of a confirmed high- or critical-severity report; up to 90 days for medium; up to 180 for low. We'll credit you in a post-fix disclosure if you want, or keep the report private if you prefer.

If we can't ship a fix in the committed window (rare, but it happens when a vendor patch is blocking), we'll tell you before the deadline and agree on an extension. We don't leave researchers guessing.

5. Bounties

We don't run a standing bug-bounty program yet, but we do discretionary awards for high-impact reports. The baseline is a public credit + SignalFloor-branded swag; anything exploitable against production payments or user accounts tends to unlock a cash reward we negotiate at the time of the fix. If bounty economics matter to you, we prefer you say so up front so nobody feels misled.

6. PGP / encrypted report

If your report includes sensitive customer data or an exploitable chain, reply to the initial ack from security@signalfloor.com and we'll share a one-time encrypted channel (Signal, ProtonMail, or a Keybase room). We don't publish a standing PGP key — rotating them is operationally painful and on-demand sharing has worked better for the reports we've received.

SignalFloor

SignalFloor – 交易创作者平台。已验证频道、课程与直播室,附完整已平仓交易历史。

创作者专题

  • 市场
  • ·排行榜
  • ·信号
  • ·按专长
  • ·外汇创作者
  • ·加密创作者
  • ·股票创作者
  • ·指数创作者
  • ·大宗商品创作者
  • ·精选榜单
  • ·最佳外汇
  • ·最佳加密
  • ·最佳已验证
  • ·EUR/USD 信号
  • ·GBP/USD 信号
  • ·BTC/USD 信号
  • ·XAU/USD 信号
  • ·PPS 公式
  • ·Creator Fit
  • ·等级公式
  • ·对比
  • ·术语表
  • ·新手入门
  • ·Signal Engine 规则
  • ·状态
  • ·更新日志
  • ·品牌
  • ·API 文档
  • ·交易日记

导航

功能 频道 创作者 排行榜 Courses Learn Live 定价 面向创作者 入门指南 关于

资源

运作方式 PPS 计算公式 什么是交易信号? SignalFloor可靠吗? 博客 所有指南 交易计算器 下载应用

法律

联系我们 条款 隐私 风险披露 退款政策
语言

© 2026 SignalFloor. 版权所有。

v1.7.0