Reporting a vulnerability.
If you have found a security problem in Apiboo, we want to hear about it — and we will work with you to get it fixed.
How to report
Email us at security@apiboo.com. Please report privately and give us a reasonable chance to fix the issue before disclosing it publicly.
What to include
- What you found and why you believe it is a security issue
- Steps to reproduce it — a proof of concept is ideal
- The affected product and version (desktop app, API, website or browser extension)
- Your assessment of the impact, if you have one
What to expect from us
- We acknowledge your report within 3 working days
- We confirm the issue and give you an assessment within 10 working days
- We keep you updated while we work on a fix, and tell you when it ships
- We credit you when the fix is released, unless you would rather stay anonymous
Safe harbour
We will not pursue legal action against anyone who reports a vulnerability in good faith, stays within the scope below, does not access or modify other people’s data, and gives us reasonable time to respond.
Scope
In scope:
- apiboo.com, api.apiboo.com, auth.apiboo.com and our regional WebSocket endpoints
- The Apiboo desktop app and its local bridge
- The Apiboo Vault browser extension
Out of scope: denial-of-service and volumetric testing, social engineering of our staff or customers, physical attacks, and reports produced solely by automated scanners without a demonstrated impact.
Bug bounty
We do not run a paid bug bounty programme yet. We do credit reporters, and we are grateful for every report.
Machine-readable contact details: /.well-known/security.txt
