1. How to report
Email [email protected] with a clear write-up of the issue, reproduction steps, and any artifacts (videos, screenshots, scripts). Use our PGP key (published at /security) for sensitive reports.
Legal · Last updated June 9, 2026
If you’ve found a security issue in Vibely, we want to hear from you. This policy explains how to report it safely and what you can expect from us in return.
Email [email protected] with a clear write-up of the issue, reproduction steps, and any artifacts (videos, screenshots, scripts). Use our PGP key (published at /security) for sensitive reports.
Reports are eligible if they affect:
The following are typically not eligible:
While testing, you must:
We acknowledge reports within 2 business days, share a triage update within 7 days, and aim to remediate critical issues within 30 days. We will credit researchers who request it once a fix has shipped.
We will not pursue legal action against researchers who follow this policy in good faith. If a third party initiates action against you for activity covered by this policy, we will make our position public.
Vibely runs a private bounty program for high-impact issues. Payouts depend on severity, exploitability, and quality of the report. Eligibility is at our discretion and requires compliance with this policy.