| Version | Supported |
|---|---|
| latest | ✅ |
Do not open a public GitHub issue for security vulnerabilities.
Please report security issues by emailing security@promptly.app with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fix (optional)
You will receive a response within 48 hours. We aim to release a patch within 7 days for critical issues.
- SQL injection, XSS, CSRF, authentication bypass
- Secrets exposure in logs or API responses
- Insecure direct object references
- Rate limiting bypass
- Issues in third-party dependencies (report upstream)
- Social engineering
- Physical security
We appreciate responsible disclosure and will credit researchers in release notes if desired.