Skip to content

Security: ananthanarayanan431/promptly

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report security issues by emailing security@promptly.app with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fix (optional)

You will receive a response within 48 hours. We aim to release a patch within 7 days for critical issues.

Scope

  • SQL injection, XSS, CSRF, authentication bypass
  • Secrets exposure in logs or API responses
  • Insecure direct object references
  • Rate limiting bypass

Out of Scope

  • Issues in third-party dependencies (report upstream)
  • Social engineering
  • Physical security

We appreciate responsible disclosure and will credit researchers in release notes if desired.

There aren't any published security advisories