Vulnerability Disclosure
If you believe you have found a security issue in repod, report it to support@repod.dev.
What To Include
- A concise description of the issue and affected URL or endpoint.
- Steps to reproduce, including any required account state or permissions.
- Potential impact and any evidence you can safely share.
- Your preferred contact details for follow-up.
Rules Of Engagement
- Do not access, modify, delete, or exfiltrate data that does not belong to you.
- Do not run denial-of-service tests, spam, social engineering, or physical attacks.
- Do not test against third-party systems except where they are clearly part of your own account setup.
- Give us reasonable time to investigate before public disclosure.
Safe Harbour
If you act in good faith, follow this policy, avoid privacy harm and service disruption, and promptly report what you find, we will not pursue legal action against you for the security research itself. This does not authorise access to third-party systems, customer data that is not yours, denial-of-service activity, extortion, or conduct that is unlawful outside this policy.
Response
We aim to acknowledge credible reports within 5 business days and will prioritize issues based on severity, exploitability, and customer impact. We may ask for more detail, provide status updates where practical, and coordinate remediation timing for confirmed issues. repod does not currently operate a paid bug bounty program.
Security Contact Metadata
Automated tooling can also use /.well-known/security.txt.