Responsible disclosure
Ce document n’existe qu’en anglais. Seule la version anglaise fait foi.
> DRAFT — not reviewed by a lawyer. Placeholders in [brackets] must be filled in by the owner before publishing.
Responsible Disclosure Policy
Last updated: October 11, 2026
We build a tool that checks other people's apps for security problems, so we take problems in our own very seriously. If you find a vulnerability in OkayToShip, please tell us.
How to report
Email security@okaytoship.com with:
- what you found and where (URL, endpoint, or component);
- steps to reproduce;
- what impact you think it has.
Please don't include real personal data or full secrets in the report. Masked examples are fine.
We'll confirm we got your report within 3 business days and keep you updated until it's fixed.
In scope
- okaytoship.com and its subdomains.
- The OkayToShip scanner's behaviour (for example, a way to make it scan something it shouldn't, or reach internal addresses).
- Sign-in, account access, report access, and payment flows.
Out of scope
- Apps scanned by OkayToShip. Report those to their owners.
- Third-party services we use (Lemon Squeezy, Railway, Resend, Cloudflare, PostHog). Report to them directly.
- Social engineering, physical attacks, denial of service or volume testing.
- Missing best-practice headers without a demonstrated impact, self-XSS, or issues needing an already-compromised device.
Please
- Test only against your own account and data.
- Don't access, change or delete other users' data. If you hit it by accident, stop and tell us.
- Don't degrade the service for others.
- Give us reasonable time to fix the issue before you disclose it publicly.
Our promise
If you act in good faith and follow this policy, we won't take legal action against you for your research and will credit you publicly if you want. We don't run a paid bug bounty at this time.
security.txt
We publish contact details at `/.well-known/security.txt`.