Security Policy
Report privately
Report suspected security issues privately. Do not open a public issue containing exploit details, secrets, signed URLs, private user data, or proof-of-concept output.
Email security@budwise.app.
In scope
Relevant reports include broken access control, private-sharing leaks, upload or signed-URL bypasses, sensor authentication bypasses, exposed credentials, authentication problems, and high-impact dependency or browser-policy issues.
Safe testing
Use local, development, demo, or researcher-owned test data. Do not exfiltrate or disclose real user data, cookies, signed URLs, service credentials, private photos, or sensor credentials.
Out of scope
Do not perform destructive production testing, denial-of-service testing, spam, social engineering, physical attacks, or scanner-only reports without reachable impact.
