security

Reporting a security issue

If you think you have found a vulnerability in SignalPipe, email contact@signalpipe.io with the steps to reproduce it and the impact you observed. Please don’t disclose it publicly until we have had a chance to fix it.

In scope

What we ask

What to expect

We read every report. When a report shows a real impact, we reply, tell you what we found and let you know when it is fixed.

We don’t run a paid bug bounty program.

Machine-readable contact: /.well-known/security.txt