Vulnerability Disclosure
Last updated: 2026-07-10
Draft. This document was prepared without a lawyer and is not legal advice; bracketed placeholders will be completed before production.
We welcome good-faith security research and appreciate responsible disclosure. Below is how to report an issue and our safe-harbor terms. Machine-readable version: /.well-known/security.txt.
1. How to report
Send reports to security@tikaboo.app. Please include reproduction steps, potential impact, and a proof-of-concept where possible. Do not disclose the vulnerability publicly before it is fixed.
2. Scope
In scope: tikaboo.app and our API. Out of scope (roughly): denial of service (DoS/DDoS), social engineering, physical attacks, and vulnerabilities in third-party services. [Confirm scope with the team.]
3. Safe harbor
We will not pursue legal action against researchers for good-faith testing conducted under this policy: without accessing others’ data beyond what is necessary, without disrupting the service, and without exfiltrating or destroying data.
4. What not to do
- access, modify, or delete other users’ data;
- disrupt the service or degrade it for others;
- use a vulnerability beyond the minimum needed to confirm it;
- disclose the vulnerability publicly before an agreed timeline.
5. Our response
We will acknowledge receipt within a reasonable time and work toward a fix under a coordinated-disclosure model. We may credit you in our acknowledgements (optional).
6. Contact
Security: security@tikaboo.app · /.well-known/security.txt