If you discover a security vulnerability, please report it responsibly:
- Email: mithungowda.b7411@gmail.com
- Do NOT open a public issue for security vulnerabilities
We will acknowledge your report within 48 hours and provide a fix as soon as possible.
This project does not have a bug bounty program. We appreciate responsible disclosure but cannot offer monetary rewards.
- Supabase RLS policy bypasses
- XSS or injection vulnerabilities in form inputs
- Exposed credentials or secrets
- The Supabase anon key is intentionally public (it only allows inserts)
- Client-side code is fully visible by design (static site)
- Issues that require physical access to the user's device