Trust
Security
We take the security of Stattribute and our users' data seriously. If you believe you've found a vulnerability, we'd genuinely like to hear from you.
How to report
Email security@stattribute.com with a description of the issue, the steps to reproduce it, its potential impact, and how we can reach you. Please give us a reasonable amount of time to investigate and fix the issue before any public disclosure.
What to include
- A clear description of the vulnerability and where you found it.
- Steps to reproduce, and a proof of concept if you have one.
- The impact you believe it could have.
Our commitment
- We'll acknowledge your report as quickly as we can.
- We'll keep you updated as we work on a fix.
- We're happy to credit you once the issue is resolved, if you'd like.
- We won't pursue legal action against good-faith research that follows this policy.
Scope
In scope: stattribute.com and our public API. Out of scope: denial-of-service (DoS/DDoS), spam, social engineering, and attacks requiring physical access.
Please do not
- Access, modify, or delete data that isn't yours.
- Degrade or disrupt the service for other users.
- Publicly disclose an issue before we've had a chance to address it.
Thank you for helping keep Stattribute and its community safe.