Skip to content

Security

Vulnerability disclosure

If you believe you have found a security vulnerability in houdin.io or app.houdin.io, we want to hear about it. This page explains how to reach us and what to expect.

1. How to report

Send your report to the address below. To keep it away from scrapers, it is only revealed on click.

2. What to include

  • A description of the issue and its impact
  • Steps to reproduce, or a proof of concept
  • The affected URL, endpoint or component
  • Your name or handle if you would like credit

3. What to expect

  • An acknowledgement within 5 business days
  • No legal action for good-faith research that respects user data and service availability
  • Credit on request once the issue is fixed

4. No paid bounties

We do not run a paid bug bounty program. Reports of the following will not receive a response: missing SPF, DKIM or DMARC records, missing security headers, clickjacking on static pages, software version disclosure, or raw automated scanner output without a demonstrated impact.