Skip to main content
security · responsible disclosure

Found something? Tell us.

We read every security report. If you report a real vulnerability, we'll fix it fast, credit you (if you want), and never take legal action against you.

How to report

Email security@brainback.chat with:

  • A short description of the vulnerability and its impact
  • Steps to reproduce (screenshots, curl commands, or a short screencast)
  • The affected URL and, if it’s account-specific, an account you created for testing
  • Optional: a suggested fix

PGP is available on request. If you can’t use email, write to us and we’ll set up a Signal thread.

What you can expect from us

  • Acknowledgment within 3 business days. A real human, not a form response.
  • A first assessment within 7 business days. We’ll tell you whether we’re treating it as a vulnerability, what severity we’re assigning, and an initial ETA.
  • No legal action as long as you follow the rules below.
  • Credit in our Hall of Fame if you’d like it (or anonymous if you prefer).
  • No monetary bounty yet. We’re a small team. We may add one later.

Scope — in

  • brainback.chat and *.brainback.chat
  • The Brainback web application at app.brainback.chat (and www.brainback.chat/app)
  • Our API endpoints at brainback.chat/api/*
  • Anything that leaks another user's data, sessions, tokens, files, or messages
  • Authentication or authorization bypass
  • Cross-site scripting, SSRF, RCE, SQL injection, IDOR
  • Business-logic flaws that let one user act on another's behalf

Scope — out

  • Third-party services we integrate with (Supabase, Vercel, Stripe, Anthropic, PostHog, Resend) — please report those to the vendor directly
  • Rate-limit / brute-force reports on public endpoints without a working PoC
  • Missing HTTP headers on marketing pages with no security implication (e.g., X-XSS-Protection deprecation notices)
  • Denial-of-service or volumetric attacks — do not test these against production
  • Physical, social-engineering, or phishing attacks against our team
  • Reports from automated scanners without demonstrable impact

Rules of engagement

  1. Test only against accounts you own. Do not access, modify, or delete data belonging to other users.
  2. Report the issue to us before publishing anywhere else. Give us 90 days to remediate before public disclosure.
  3. Do not exfiltrate data. If you accidentally see data belonging to another user, stop and report it.
  4. Do not degrade the service. No DoS, no automated fuzzing of production, no spam through our transactional email.
  5. Follow all applicable laws.

Hall of Fame

Researchers who have helped make Brainback safer. If you want to appear here (or be updated), email us.

Be the first. We’ll add you here with a link of your choice.

Machine-readable

This policy is published at /.well-known/security.txt per RFC 9116.