Security
We take the security of Camwarden seriously. If you've discovered a vulnerability, we'd like to hear from you.
Reporting a Vulnerability
Please email [email protected] with the subject line Security Disclosure. Include:
- A description of the vulnerability
- Steps to reproduce it
- The potential impact
We accept reports in English.
What to Expect
- Acknowledgement within 3 business days
- We'll keep you updated as we investigate and work toward a fix
- We aim to resolve confirmed vulnerabilities as quickly as possible, depending on severity and complexity
We're a small team, so we appreciate your patience.
Scope
In scope:
- camwarden.com and all subdomains (cdn.camwarden.com, etc.)
- The Camwarden web application
Out of scope:
- Third-party services we build on
- Camwarden social media accounts
- Denial-of-service attacks
- Spam or social engineering
Ground Rules
We ask that you:
- Don't exploit the vulnerability beyond what's needed to demonstrate it
- Don't access, modify, or exfiltrate real user data
- Give us reasonable time to fix the issue before any public disclosure (we follow the 90-day industry norm)
In return, we won't pursue legal action against researchers who act in good faith.
Acknowledgements
We thank the following security researchers for their responsible disclosures:
None yet — be the first.