Draft — to be reviewed by counsel before publication

Vulnerability disclosure

Report a security issue in this service to security@sendtier.com. Counsel reviews this policy before it is public. The fields to publish in security.txt are in docs/security/security-txt.md.

Owner action: verify that security@sendtier.com receives mail before launch. This policy does not prove the mailbox is monitored.

How to report

Email security@sendtier.com. Include:

Do not include message bodies, recipient lists, or other people's personal data in the report. Refer to a tenant by its tn_ id. Do not include a live API key. If a key was exposed, say so. An owner can revoke a key with a full-scope key. There is no unauthenticated revoke route. Write to security@sendtier.com with the key id (key_ prefix) and we will revoke the row.

Scope

In scope when the hosts exist:

Out of scope:

The production host names are to confirm. Do not treat an example host in the spec as in scope.

Rules for research

What we will do

We will acknowledge the report. A target time for the acknowledgement is to confirm by counsel. We will investigate and, when we confirm the issue, we will work on a fix. We will credit you if you want credit and counsel agrees. We do not run a paid bounty. Do not state a reward.

Safe harbor, draft, to confirm by counsel: we will not bring a claim against you for research that followed this policy, stayed in scope, and avoided harm to other customers. This sentence does not bind a court until counsel publishes it. It does not cover access to other tenants, extortion, or destruction of data.

Production contact file

Publish Contact and Expires. RFC 9116 requires both. Also publish Preferred-Languages, Canonical, and Policy, as docs/security/security-txt.md describes. The site serves this page at /security/. Policy points there.