Skip to main content
For families who want their stories to last. learn about the founding circle.
← Trust Centre
Honest posture

Bug bounty

Public bounty launches when we can triage fairly. Private disclosures welcomed today.

We take security reports seriously. A public bug-bounty programme opens once there's the staffing to triage inside 48 hours. Until then, please disclose privately. We'll credit you, with your permission, and pay where the policy below says we pay.
Programme status: privatePublic launch: plannedDisclosure: responsible, 90-day default

If we can’t keep a promise yet, it gets written here first.

How to reach us

One email, one PGP key.

Send reports to security@confinity.com. Include a proof of concept, the affected URL, and any fix you’d suggest. If the report carries somebody's personal data, even inside the proof of concept, tell us first. We'll agree a channel. The PGP key published at /.well-known/pgp-key.txt is a placeholder and won’t decrypt anything, so please don’t rely on it. A real key replaces it before the public programme opens.
security@confinity.com
PGP key: placeholder
Acknowledgement inside 72 hours

Scope

In scope and out of scope.

In scope

  • *.confinity.com web properties
  • /app signed-in surfaces
  • /api/* public endpoints
  • Authentication flows (sign-in, session handling, CSRF)
  • Payment flows (Founding Circle checkout)
  • Mobile + desktop apps once they are public

Out of scope

  • Third-party services we link to (report to them directly)
  • Social engineering of staff (we will not pay for this)
  • Physical attacks on our premises or personnel
  • Denial-of-service testing without prior written authorisation
  • Automated scanner output without a working proof of concept

Severity

How we classify and reward.

  • Critical

    Top of range (published at public launch)
    Account takeover, full data exfiltration, PII exposure at scale
  • High

    Meaningful (published at public launch)
    Authorisation bypass, content tampering, XSS on authenticated pages
  • Medium

    Credit + modest bounty
    CSRF without state change, reflected XSS on marketing surfaces
  • Low

    Credit only
    Information disclosure without PII, minor misconfiguration

Safe-harbour rules

  • Good-faith testing inside this scope won't be treated as a breach of our terms. You have our word on that in writing.
  • Please don't access, change or keep data that isn't yours. Stop the moment the vulnerability is demonstrated.
  • Public disclosure may happen after the 90-day default window. Sooner, if we both agree.

More honesty

Looking for more?

The Trust Centre indexes every honest document we publish, and the binding legal ones sit below it.