Security Responsible disclosure

Security Policy

This page explains how to report security issues to Vibe Check and Chat, what good-faith research looks like, and how coordinated disclosure is handled.

We accept private reports, review them promptly, and coordinate disclosure before any public discussion of a real vulnerability.

Contact: security@didyouvibecheck.com Policy window: 90 days Reference: /.well-known/security.txt
Policy

Reporting process

Email security@didyouvibecheck.com with a clear description of the issue, steps to reproduce, any proof-of-concept material you can share safely, and your preferred contact method for follow-up.

Do not post findings publicly before we have a chance to review them. Responsible disclosure begins with private contact.

Policy

Responsible disclosure timeline

We aim to acknowledge receipt within 48 hours.

We aim to provide an initial assessment within 5 business days.

Our default coordinated disclosure window is 90 days unless a different timeline is agreed with the reporter.

If a report is valid and you want public credit, we will coordinate acknowledgment with you.

Policy

Scope

This policy applies to Vibe Check and Chat production properties, including didyouvibecheck.com, chatworkforce.com, and directly operated subdomains.

It does not apply to third-party services we depend on, including AI compute, cloud hosting, payment processing, and data infrastructure providers, unless the issue is specifically caused by our integration or configuration.

In scope: authentication and authorization flaws, injection and SSRF issues, deserialization, access-control failures, secrets exposure, sensitive-data leakage, privilege escalation, and security flaws in public proof or reporting surfaces that affect confidentiality or integrity.

Out of scope: social engineering, physical attacks, denial-of-service attempts, findings that only affect third-party services we consume, and purely theoretical issues without plausible security impact.

Policy

Recognition

We will acknowledge valid reports if the reporter wants recognition and if doing so is consistent with disclosure timing, customer safety, and any active remediation work.

Policy

Good-faith legal safe harbor

Good-faith research conducted under this policy is welcome. We will not pursue legal action against researchers who avoid privacy violations and service disruption, do not access more data than necessary to demonstrate the issue, report promptly and privately before public disclosure, and do not exploit findings for any purpose other than responsible disclosure.

This safe harbor does not authorize destructive testing, privacy violations, extortion, or persistence beyond what is necessary to demonstrate the issue.