Security & Vulnerability Disclosure
Last updated
We take reports of security vulnerabilities seriously and appreciate the work of good-faith security researchers. This page explains how to report a vulnerability and what protection you have for doing so responsibly.
How to report
Email security@vibld.com with a description of the issue, the steps to reproduce it, and its potential impact. Please encrypt sensitive reports if possible, and avoid including data that is not your own beyond what is necessary to demonstrate the issue. A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.
What to expect
- We will acknowledge a report within 3 business days.
- We will investigate and keep you reasonably informed of progress.
- We will let you know once the issue is resolved, and we welcome being credited unless you prefer otherwise.
Safe harbor
We will not pursue legal action against you for good-faith security research conducted in accordance with this policy, including testing, identifying, and reporting a vulnerability, provided that you:
- Avoid privacy violations, destruction of data, and interruption or degradation of the Service;
- Only interact with accounts and data you own or have explicit permission to access;
- Give us a reasonable time to investigate and remediate before disclosing the issue publicly; and
- Do not exploit a vulnerability beyond what is necessary to confirm it exists.
This safe harbor does not extend to third-party services we use (see our Subprocessors page) — report an issue in one of those directly to its own provider.
Scope
Today, this policy covers this website (https://vibld.com). Once the Vibld application and hosted previews launch, this page will be updated to describe their scope specifically, including how untrusted, AI-generated code is isolated.