Security
Security and vulnerability disclosure
How to report a vulnerability, what is in scope, and how this site protects you.
Report a vulnerability
Email sales@apysyk.com. Please include:
- what you found, and where: the address, endpoint or service;
- the steps to reproduce it;
- the impact, as you understand it;
- any proof of concept, such as requests, responses or screenshots;
- how we can reach you.
Reports in English or Portuguese are welcome.
Scope
In scope
- apysyk.com;
- the services Apysyk operates on subdomains of apysyk.com.
Out of scope
- denial of service;
- spam;
- social engineering;
- physical attacks;
- third-party services, such as AWS, Google, Auth0 and GitHub. Report issues in them to their owners.
Testing guidelines
- Use only accounts and data that are yours, or that you have permission to use.
- Access, change or delete no more data than you need to show the issue. If you reach someone else’s data, stop and tell us.
- Do not degrade the service for other people.
- Keep the details private while we work on a fix, as described in Disclosure.
Disclosure
Please give us reasonable time to fix the issue before you disclose it.
Rewards
We do not offer a paid bug bounty at this time.
How this site is protected
- HTTPS everywhere, with HSTS.
- A strict Content Security Policy that allows only our own origin.
- No third-party code on the site: no analytics, ads or trackers.
- The demo form endpoint accepts requests only through our CDN, with rate limits per IP address.
- Demo requests go to an inbox whose access is limited to our team.
How we handle personal data is in the Privacy Policy.