Early accessSuperPost is in early access. Sign up to get early-bird pricing locked for life.Lock pricing →
superpost
Security

Vulnerability disclosure policy.

Found a security issue? Email security@superpost.io. A human reads every report within 24 hours. Below is what to send, what we promise back, and what's in vs. out of scope.

RFC 9116 record: /.well-known/security.txt

Reporting a finding

  1. Email security@superpost.io.
  2. Include: a short description, reproduction steps, the affected URL or endpoint, the impact you can demonstrate, and any PoC payloads.
  3. If the finding involves customer data, stop. Tell us the path you took to reach it and we'll reproduce in a test workspace.
  4. Do not file the report as a public GitHub issue or post on social media before we coordinate disclosure.

Response SLAs

WindowCommitment
24 hoursAcknowledgement of receipt — a human reads every report.
7 daysInitial triage with a severity assignment + remediation owner.
Per severityFix targets: critical ≤ 7d, high ≤ 14d, medium ≤ 60d, low + informational normal sprint cadence.
On resolutionWe coordinate disclosure timing with you. Default: public credit on /security/acknowledgments after the fix ships.

SLAs above mirror what we enforce for paid pen test engagements — see infra/pentests/lint.py in the public repo for the mechanical SLA gate.

In scope

Out of scope

Safe harbor

This is not yet a paid bug bounty — we credit researchers on /security/acknowledgments and may offer swag or a public reference. A formal bounty program launches once volume justifies it.