Skip to content

Legal · Last updated June 9, 2026

Responsible Disclosure

If you’ve found a security issue in Vibely, we want to hear from you. This policy explains how to report it safely and what you can expect from us in return.

1. How to report

Email [email protected] with a clear write-up of the issue, reproduction steps, and any artifacts (videos, screenshots, scripts). Use our PGP key (published at /security) for sensitive reports.

2. Scope

Reports are eligible if they affect:

  • vibely.app and *.vibely.app web surfaces.
  • The Vibely API at api.vibely.app.
  • Preview hosts at *.vibelyagent.com.

3. Out of scope

The following are typically not eligible:

  • Self-XSS, clickjacking on pages without sensitive actions.
  • Reports requiring physical access to a victim’s device.
  • Best-practice findings without a working proof of concept.
  • Vulnerabilities in third-party services we depend on (report to them).
  • Volumetric denial-of-service or social-engineering attacks.

4. Rules of engagement

While testing, you must:

  • Use test accounts you control — never access another user’s data.
  • Stop and report immediately if you encounter user data.
  • Avoid disruption: no destructive testing, automated brute force, or large-scale scraping.
  • Keep findings confidential until we publish a fix or 90 days have passed.

5. What you can expect from us

We acknowledge reports within 2 business days, share a triage update within 7 days, and aim to remediate critical issues within 30 days. We will credit researchers who request it once a fix has shipped.

6. Safe harbor

We will not pursue legal action against researchers who follow this policy in good faith. If a third party initiates action against you for activity covered by this policy, we will make our position public.

7. Bounty

Vibely runs a private bounty program for high-impact issues. Payouts depend on severity, exploitability, and quality of the report. Eligibility is at our discretion and requires compliance with this policy.

Questions about this document? Email [email protected].