This policy applies to Vibe Check and Chat production properties, including didyouvibecheck.com, chatworkforce.com, and directly operated subdomains.
It does not apply to third-party services we depend on, including AI compute, cloud hosting, payment processing, and data infrastructure providers, unless the issue is specifically caused by our integration or configuration.
In scope: authentication and authorization flaws, injection and SSRF issues, deserialization, access-control failures, secrets exposure, sensitive-data leakage, privilege escalation, and security flaws in public proof or reporting surfaces that affect confidentiality or integrity.
Out of scope: social engineering, physical attacks, denial-of-service attempts, findings that only affect third-party services we consume, and purely theoretical issues without plausible security impact.