Responsible disclosure
Report a SafeForProd security issue privately.
If you believe you found a vulnerability in SafeForProd itself, send the minimum evidence needed to reproduce it. Do not publish sensitive details or test against other users.
Where to report
Email hello@safeforprod.com with the subject “Private security report.” Do not send live credentials, full customer data, or an unredacted source archive in the first message.
Include
- The affected SafeForProd URL or component.
- Clear, minimal reproduction steps and the observed result.
- The security impact you believe is possible.
- Redacted screenshots, request/response details, or a small proof of concept when needed.
- A safe way to contact you about follow-up questions.
Do not
- Access, change, download, or delete another person’s data.
- Run denial-of-service, load, spam, social-engineering, or persistence tests.
- Use automated scanning that degrades service or expands beyond the minimum target.
- Publish the issue before there has been a reasonable opportunity to understand and address it.
What happens next
The report is reviewed for reproducibility, scope, and impact. SafeForProd may ask for clarification or a safer proof. Remediation and disclosure timing depend on the issue; this page does not promise a bounty, fixed response time, or a particular outcome.