// security
Security & Responsible Disclosure
If you believe you have found a vulnerability in VibeCheck Hub, we want to hear from you. Here is how to report it safely.
Reporting a vulnerability
Email support@vibecheckhub.ai with:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, including any required accounts, payloads, or URLs.
- Your name or handle, if you would like credit.
If the issue is sensitive, request our PGP key in your first message and we will provide one.
Response targets
- Acknowledgement within 2 business days.
- Initial triage within 5 business days.
- Resolution timeline shared after triage, prioritized by severity.
These targets are goals, not contractual commitments.
Scope
In scope:
- The VibeCheck Hub web application and its public APIs.
- Authentication, session handling, and authorization flows.
- Data leakage between workspaces or users.
Out of scope:
- Volumetric denial-of-service testing, social engineering, and physical attacks.
- Self-XSS, missing security headers without a working exploit, and best-practice suggestions without impact.
- Issues on test or staging environments unless they demonstrably affect production.
Safe harbor
We will not pursue legal action against researchers who:
- Make a good-faith effort to follow this policy.
- Avoid privacy violations, service disruption, and data destruction.
- Give us a reasonable opportunity to respond before disclosing publicly.
Acknowledgements
With your permission, we will credit reporters who disclose qualifying vulnerabilities responsibly. A public acknowledgements list will appear here once the program is live.