Security
Vulnerability Disclosure Program
We take security seriously. If you find a vulnerability in Getbyliner, please tell us responsibly — we will investigate and respond as quickly as we can.
How to report
Email a clear description of the issue. Please give us a reasonable time to investigate before sharing it publicly.
Send reports to [email protected]. Include steps to reproduce, affected URLs or product areas, impact, and any proof of concept you are comfortable sharing.
Please avoid privacy-invasive testing, social engineering, denial of service, or accessing other users' data beyond what is needed to demonstrate the issue.
Recognition — not cash (for now)
Getbyliner is non-funded. We do not offer cash bounties at this time.
Valid, responsibly disclosed findings may be recognized in our Hall of Fame. From time to time we also offer exclusive perks or swag to researchers who help keep Getbyliner safe.
Recognition is at our discretion based on severity, clarity, and good-faith collaboration. Duplicate or out-of-scope reports may not qualify.
Hall of Fame
Researchers who have helped improve Getbyliner security are listed here with thanks.
No entries yet — be the first. After we validate a report, we will credit you here (with the name or handle you prefer).
Scope
- getbyliner.com and related Getbyliner application surfaces
- Authenticated product APIs used by the Getbyliner web app
- Issues that could expose user data, bypass auth, or affect other customers
Third-party services, spam/social engineering, and physical security are out of scope unless they clearly demonstrate a Getbyliner product vulnerability.