Draft policy, pending legal review
Responsible disclosure
If you have found a security problem, we would rather hear it from you than read about it later. This page says how to tell us and what we will do.
How to report
Write to security@aistayslocal.com. Include enough detail to reproduce the issue: the URL or component, the steps, and what you observed. If you have a proof of concept, describe it rather than attaching anything executable.
What we commit to
We will acknowledge your report within five working days, keep you informed while we investigate, and tell you when it is fixed. We will credit you publicly if you want that and stay quiet about you if you do not. We will not take legal action against someone who followed this policy in good faith.
We are one small team without a bug bounty programme, so there is no payment. We will say so up front rather than leaving you to discover it after the work.
In scope
This website and its infrastructure, on aistayslocal.com and its subdomains. Once a beta build exists, the desktop application and its update mechanism as well - this page will be updated when that happens.
Out of scope
Denial of service, volumetric or automated scanning that degrades the service for others, social engineering of any person, physical attacks, and reports generated by a scanner without a demonstrated impact. Please do not test against anyone else’s data, and do not access, modify or retain data that is not yours.
Disclosure
We ask for ninety days before public disclosure, and we will usually be faster than that. If we disagree about severity or timing we will tell you why, in writing, rather than going quiet.
This is a draft policy written by the product team. It has not been reviewed by a lawyer, and the safe harbour wording above in particular needs that review before it can be relied on.