Please report it privately. Do not open a public issue, and do not post details anywhere public until it is fixed.
Two ways, either is fine:
- GitHub — the Security tab opens a private advisory only the maintainers can see.
- Email — security@inkloom.art
Whatever you have. A short description and the steps to reproduce is enough; a proof of concept is welcome but not required. If you are unsure whether something is a vulnerability, report it anyway — a false alarm costs us a few minutes, and an unreported issue costs a great deal more.
| Acknowledgement | within 3 working days |
| First assessment | within 7 working days |
| Fix or a dated plan | within 30 days for anything we rate high or critical |
We will tell you what we found, what we changed, and when it shipped. If we decide something is not a vulnerability we will say why rather than go quiet.
In scope: inkloom.art, the API beneath it, and this repository.
Out of scope, because they are not ours to fix: Cloudflare, Neon, Resend and GitHub themselves — report those to the vendor. Also out of scope: reports generated by a scanner with no demonstrated impact, missing headers with no exploit path, and anything requiring physical access to a user's unlocked device.
Stay inside your own account. Do not access, modify or delete anyone else's data. Do not run denial-of-service tests, automated scanning that degrades the service, or social engineering against anyone. Give us reasonable time to fix an issue before disclosing it.
Do that, and we will treat your report as good-faith research and will not pursue action over it.
We are glad to name you in the advisory and the release notes if you would like that, and equally glad not to. Tell us which.
Some things are known and deliberate rather than undiscovered — generation and payments are not built, and the flags that would enable them default to off. If a report depends on a feature that does not exist yet, say so and we will tell you where it stands.
There is no paid bounty programme at this stage. We would rather say so plainly than imply one.