Security

Security and vulnerability disclosure

How to report a vulnerability, what is in scope, and how this site protects you.

Last updated security.txt

Report a vulnerability

Email sales@apysyk.com. Please include:

  • what you found, and where: the address, endpoint or service;
  • the steps to reproduce it;
  • the impact, as you understand it;
  • any proof of concept, such as requests, responses or screenshots;
  • how we can reach you.

Reports in English or Portuguese are welcome.

Scope

In scope

  • apysyk.com;
  • the services Apysyk operates on subdomains of apysyk.com.

Out of scope

  • denial of service;
  • spam;
  • social engineering;
  • physical attacks;
  • third-party services, such as AWS, Google, Auth0 and GitHub. Report issues in them to their owners.

Testing guidelines

  • Use only accounts and data that are yours, or that you have permission to use.
  • Access, change or delete no more data than you need to show the issue. If you reach someone else’s data, stop and tell us.
  • Do not degrade the service for other people.
  • Keep the details private while we work on a fix, as described in Disclosure.

Disclosure

Please give us reasonable time to fix the issue before you disclose it.

Rewards

We do not offer a paid bug bounty at this time.

How this site is protected

  • HTTPS everywhere, with HSTS.
  • A strict Content Security Policy that allows only our own origin.
  • No third-party code on the site: no analytics, ads or trackers.
  • The demo form endpoint accepts requests only through our CDN, with rate limits per IP address.
  • Demo requests go to an inbox whose access is limited to our team.

How we handle personal data is in the Privacy Policy.