Responsible disclosure

Report a SafeForProd security issue privately.

If you believe you found a vulnerability in SafeForProd itself, send the minimum evidence needed to reproduce it. Do not publish sensitive details or test against other users.

Where to report

Email hello@safeforprod.com with the subject “Private security report.” Do not send live credentials, full customer data, or an unredacted source archive in the first message.

Include

  • The affected SafeForProd URL or component.
  • Clear, minimal reproduction steps and the observed result.
  • The security impact you believe is possible.
  • Redacted screenshots, request/response details, or a small proof of concept when needed.
  • A safe way to contact you about follow-up questions.

Do not

  • Access, change, download, or delete another person’s data.
  • Run denial-of-service, load, spam, social-engineering, or persistence tests.
  • Use automated scanning that degrades service or expands beyond the minimum target.
  • Publish the issue before there has been a reasonable opportunity to understand and address it.

What happens next

The report is reviewed for reproducibility, scope, and impact. SafeForProd may ask for clarification or a safer proof. Remediation and disclosure timing depend on the issue; this page does not promise a bounty, fixed response time, or a particular outcome.