Security
Reporting a security problem
Last updated 15 September 2026
If you think you have found a security vulnerability in Cardonomics, please tell us. We read every report, and we will not take action against people who look for problems in good faith and report them to us responsibly.
How to report
Email [email protected]. Please include:
- what the problem is and what someone could do with it;
- the steps, requests or proof of concept needed to reproduce it, with the pages or addresses involved;
- any account you used to test (your own), and roughly when you tested;
- how you would like to be credited, if at all.
Please do not report vulnerabilities through public channels, social media or support tickets. Our machine-readable contact file is at /.well-known/security.txt.
What is in scope
- The Cardonomics website at cardonomics.io and www.cardonomics.io;
- its API under /api/, including sign-in, sessions, password reset, account settings, data export and deletion;
- our side of billing and Google sign-in (how we start them and handle what comes back).
Out of scope
- Services run by other companies, including our payment, hosting, email, DNS and sign-in providers and any streaming platform or marketplace. Report those to the company concerned.
- Denial-of-service or load testing, and anything that degrades the site for others.
- Social engineering, phishing or physical attacks on us, our providers or our users.
- Reports from automated scanners with no demonstrated impact, missing best-practice headers with no exploit, and self-XSS.
- Spam, or rate limits on actions with no security effect.
Testing rules
- Only test against accounts you own or have the account holder's permission to use.
- Do not access, change, download or delete other people's data. If you reach data that is not yours, stop, do not keep a copy, and tell us.
- Use the minimum access needed to show the problem. Do not keep access open.
- Do not scrape or bulk-download data, and do not run tests that could harm the service or its data.
- Keep the details private until we have fixed the problem, or until 90 days after your report, whichever is sooner, unless we agree otherwise with you.
Safe harbor
If you make a good-faith effort to follow this policy while researching and reporting a vulnerability, we will consider your research authorised. We will not bring legal action against you, and we will not report you to law enforcement, for that research. If a third party takes legal action against you for research that followed this policy, we will make it known that your actions were authorised by us.
This does not cover actions that break these rules or the law in other ways, such as accessing other people's data, extortion, or disrupting the service. We cannot authorise testing of systems that belong to other companies. If you are unsure whether something is allowed, ask us first.
What happens after you report
- Within 3 business days: we confirm we have received your report.
- Within 10 business days: we tell you whether we can reproduce it and how serious we think it is.
- At least every 30 days until it is resolved, we tell you where things stand.
- We aim to fix serious problems as fast as we can, and to fix confirmed problems within 90 days. We will tell you when a fix is live.
We do not currently run a paid bug bounty. With your permission, we are happy to thank you by name once a problem is fixed.
More about how we protect data
Our Privacy Notice describes the security measures we use and what we do if personal information is ever exposed.