Help us keep Reedsy secure

If you discover a valid vulnerability in a Reedsy-owned product or service, report it responsibly and we will review it promptly. Eligible reports may receive a reward.

Send reports to security@reedsy.com

Include a clear description of the issue, the affected URL or product, step-by-step reproduction instructions, and any proof of concept. Please submit verifiable evidence that helps us validate the finding, such as screen captures, videos or logs.

Reward tiers

Severity Reward Examples
Low $10 Informational issues or small-impact flaws.
Medium $25 Issues with limited security impact.
High $50 Issues that can expose protected data or privileges.
Critical $100 Issues that can lead to account takeover or broad compromise.

Final rewards depend on severity, impact, reproducibility, report quality, and whether the issue was previously known.

Duplicate reports generally do not receive a reward. If someone else has already reported the same issue, we will mark it as a duplicate and only reward the earliest valid submission.

Scope

In scope are Reedsy-owned applications, public websites, APIs, and services that are reachable over the internet. If you are unsure whether something is in scope, ask first before testing.

Typical examples include account flows, authentication, authorization, file handling, payment-related integrations, and any public-facing functionality that could affect user data or platform integrity.

Out of scope

We do not reward reports for the following unless they demonstrate a concrete, exploitable security impact:

  • Denial-of-service testing, rate-limit probing, or load testing.
  • Non-security bugs, feature requests, usability issues, and general product feedback.
  • Social engineering, phishing, physical attacks, or attacks against employees or contractors.
  • Issues requiring physical access, intercepted traffic on a user-owned network, or access to another party's accounts or devices.
  • Low-risk findings such as missing security headers, verbose error messages, or hardening suggestions without an exploit path.
  • Reports that only describe generic best practices or duplicate a previously reported issue.

Rules of engagement

Please test responsibly. Do not access, modify, or destroy data that does not belong to you, and do not try to move from the issue you found into other accounts, services, or infrastructure. Check with us first before trying something that could cause significant disruption.

Keep the proof of concept as minimal as possible, stop once you have confirmed the impact, and avoid disrupting service for other users. Coordinate any public disclosure with us after we have had a reasonable chance to fix the issue.

Safe harbor

If you follow this policy, we will treat your research as authorized and will not initiate legal action or revoke access solely because you made a good-faith report. This safe harbor does not cover actions that violate the law, compromise user data, or are outside the scope of this policy.

How we handle reports

We aim to acknowledge valid reports promptly, triage them, and work with you on verification and remediation. Once a report is confirmed, we may update the affected systems, adjust the bounty amount, and close the loop with you when possible.

Questions

If you have a question about the program, contact us at security@reedsy.com.