Vulnerability Disclosure

Last updated: 2026-07-10

Draft. This document was prepared without a lawyer and is not legal advice; bracketed placeholders will be completed before production.

We welcome good-faith security research and appreciate responsible disclosure. Below is how to report an issue and our safe-harbor terms. Machine-readable version: /.well-known/security.txt.

1. How to report

Send reports to security@tikaboo.app. Please include reproduction steps, potential impact, and a proof-of-concept where possible. Do not disclose the vulnerability publicly before it is fixed.

2. Scope

In scope: tikaboo.app and our API. Out of scope (roughly): denial of service (DoS/DDoS), social engineering, physical attacks, and vulnerabilities in third-party services. [Confirm scope with the team.]

3. Safe harbor

We will not pursue legal action against researchers for good-faith testing conducted under this policy: without accessing others’ data beyond what is necessary, without disrupting the service, and without exfiltrating or destroying data.

4. What not to do

  • access, modify, or delete other users’ data;
  • disrupt the service or degrade it for others;
  • use a vulnerability beyond the minimum needed to confirm it;
  • disclose the vulnerability publicly before an agreed timeline.

5. Our response

We will acknowledge receipt within a reasonable time and work toward a fix under a coordinated-disclosure model. We may credit you in our acknowledgements (optional).

6. Contact

Security: security@tikaboo.app · /.well-known/security.txt