01Scope
The following systems and surfaces are included in our responsible-disclosure program. Reports outside the listed scope will still be triaged, but do not qualify for safe-harbor protections under this policy.
In scope
- devprop.io and all *.devprop.io subdomains
- panel.devprop.io admin console
- guide.devprop.io documentation portal
Out of scope
- Third-party services we depend on (Stripe, Google Analytics, Cloudflare, hosting provider)
- Social engineering, phishing of staff, or physical attacks on offices/data centers
- DoS, DDoS, and volumetric or rate-limit-stress testing
- Reports based solely on automated scanner output without a working proof-of-concept
- Missing security headers without a demonstrated exploitation path
- Vulnerabilities in software we do not operate (browser plugins, OS-level issues)
02How to report
Send a clear, reproducible report to the address below. We acknowledge every legitimate report.
What to include
- Clear description of the vulnerability and its impact
- Step-by-step reproduction instructions
- Affected URL(s), endpoints, or component name
- Proof-of-concept code, screenshots, or HTTP request/response capture
- Your assessment of severity (CVSS optional but appreciated)
- Your contact information for follow-up and credit
03Response SLA
We commit to the following response and remediation targets, measured from the time a valid report is received.
Acknowledgment and triage
- Triage acknowledgment: within 48 hours
- Initial validation: within 5 business days
- Status updates: at least every 7 days for active investigations
Fix targets by severity
04Safe Harbor
Good-faith security research that follows this policy is authorized and welcomed. We will not pursue legal action — civil or criminal — against researchers who:
- Make a reasonable effort to avoid privacy violations, data destruction, and degradation of service
- Use only test accounts you own or accounts with explicit permission
- Do not access, modify, or exfiltrate user data beyond the minimum required to prove the vulnerability
- Report findings promptly and give us reasonable time to remediate before any public disclosure
- Do not engage in extortion, blackmail, or demand payment in exchange for withholding a report
This safe-harbor applies to legal action initiated by us. We cannot grant immunity from third-party legal action, but if a third party brings a claim against you for research conducted in good faith under this policy, we will make our authorization clear to that party.
05Acknowledgments
Coming soon. Verified reporters will be credited here, with their consent, listed in chronological order of report receipt. If you prefer to remain anonymous, we will honor that choice.
How credit works
- Public credit by name or handle (with your permission)
- Optional link to your personal site, GitHub, or social profile
- Brief description of the class of finding (without exposing exploit details)
06Rewards
At this time we offer acknowledgment only. We do not pay monetary bounties for vulnerability reports.
A formal bug-bounty program may launch in the future. Researchers who reported high-impact issues during the acknowledgment-only period will be invited first when that program goes live.
07Encrypted contact
A PGP key for confidential disclosure is available on request. Send an email to [email protected] with the subject line PGP key request and we will reply with our current public key fingerprint and full ASCII-armored key.
For especially sensitive reports, you may also request a Signal contact or a one-time secure channel.
This policy is reviewed quarterly. Last review: 2026-06-01. RFC 9116 reference: /.well-known/security.txt