Security
Responsible Disclosure
Last updated: May 2025
Reporting a Vulnerability
If you discover a security vulnerability in OfferInbox, we ask that you report it responsibly. Please do not disclose the vulnerability publicly until we have had a reasonable opportunity to address it.
Send your report to: [security@offerinbox.com]
What to Include in Your Report
- A clear description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof of concept if applicable)
- Any affected URLs, endpoints, or components
- Your name or handle (for credit, if desired)
Our Commitments
- We will acknowledge your report within 48 hours
- We will provide a timeline for resolution within 7 days
- Critical vulnerabilities will be addressed within 30 days
- We will credit you in our security acknowledgements if you wish
- We will not pursue legal action against researchers who act in good faith under this policy
Scope
In scope:
- offerinbox.com and all subdomains
- OfferInbox web application and API
Out of scope:
- Third-party services (Neon, Cloudflare, Vercel, Google) — report these to the respective vendors
- Denial of service attacks
- Physical security attacks