Security

Vulnerability disclosure

How to report security issues in AtRisk, what we ask of researchers, and our coordinated disclosure expectations.

Last updated: September 9, 2026 · Effective: September 9, 2026

1. How to report

Email contact@atrisk.dev with a clear description of the issue, steps to reproduce, affected URLs or components, and any proof-of-concept that demonstrates impact without exploiting customer data.

Prefer encrypted or cleartext email as available; include a contact method for follow-up. Machine-readable contact details are also in /.well-known/security.txt.

2. Scope

  • In scope: atrisk.dev, app.atrisk.dev, related AtRisk APIs and Workers we operate
  • Out of scope: third-party products (Neon, Polar, Cloudflare dashboard, GitHub, model providers) except where a misconfiguration is clearly ours
  • Out of scope: social engineering of staff or customers, physical attacks, DoS/DDoS volume testing without prior written approval

3. Safe harbor (good faith)

If you research and report in good faith consistent with this policy, we will not pursue legal action against you for that research. We ask that you:

  • Only test systems you are authorized to access or that are publicly reachable for the purpose of demonstrating a vulnerability
  • Do not access, modify, or destroy data that is not yours
  • Do not disrupt availability (no volumetric DoS)
  • Do not use findings to extort, threaten, or publicly shame customers
  • Give us a reasonable chance to remediate before public disclosure

Safe harbor does not cover malicious activity, theft of data, or testing that violates applicable law outside the bounds of this coordinated disclosure process.

4. Coordinated disclosure (90 days)

We aim to acknowledge reports promptly and to remediate or mitigate within 90 days of a complete report, or to agree an alternate timeline with you. We ask researchers to wait at least 90 days (or until we confirm a fix) before public disclosure, unless we mutually agree otherwise or an actively exploited critical issue requires earlier public warning.

5. What to expect

  • Acknowledgement and triage of valid reports
  • Status updates as we investigate and fix
  • Credit in release notes or a hall of fame if you want it and the fix ships - optional
  • No guaranteed bounty payment unless we publish a separate bounty program

6. Contact

Policy effective September 9, 2026. This is a safe-harbor style program for good-faith research - not a paid bug bounty unless we separately announce one.