Skip to content

Security: DBIT-Banglore/DBIT-PageCraft

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

We will acknowledge your report within 48 hours and provide a fix as soon as possible.

Bug Bounty

This project does not have a bug bounty program. We appreciate responsible disclosure but cannot offer monetary rewards.

Scope

  • Supabase RLS policy bypasses
  • XSS or injection vulnerabilities in form inputs
  • Exposed credentials or secrets

Out of Scope

  • The Supabase anon key is intentionally public (it only allows inserts)
  • Client-side code is fully visible by design (static site)
  • Issues that require physical access to the user's device

There aren't any published security advisories