Supload — Coordinated Vulnerability Disclosure Policy Last updated: 2026-09-07 Referenced by the Policy field of the security.txt records on sup-load.com and portals.sup-load.com. A plain-language version of this policy is published at https://sup-load.com/security HOW TO REPORT Email security@sup-load.com. Include the affected URL or endpoint, the steps needed to reproduce, and what an attacker gains. Reports are read; we will acknowledge yours at the address you write from. WHAT TO EXPECT Supload is a small team, so these are targets we believe we can meet rather than a contractual service level. We aim to acknowledge your report within 3 business days, to give you a first assessment — whether we can reproduce it and how we are rating it — within 10 business days, and to tell you when it is fixed. If one of those slips, write again rather than assuming the report was ignored. IN SCOPE portals.sup-load.com customer billing and account portal sup-load.com marketing and legal site the Supload iOS application the Supabase backend those three use OUT OF SCOPE Third-party platforms and their own infrastructure (Stripe, Supabase, Apple, Google, Microsoft, Dropbox, Cloudflare). Report those to the vendor. Findings that require physical possession of an unlocked device, or a compromised operating system. Social engineering of Supload staff, customers or vendors. Denial of service, volumetric testing, and automated scanning against production. Reports consisting only of scanner output with no demonstrated impact. RULES OF ENGAGEMENT Access, modify and retain only data belonging to an account you control. Stop as soon as you have established that a vulnerability exists — do not pivot, escalate, or enumerate other customers' data to size the impact. Do not degrade service for other users. Give us a reasonable opportunity to remediate before publishing. AUTHORIZATION AND SAFE HARBOUR Security research carried out inside the scope and the rules of engagement above is authorized by Supload LLC. The Supload Terms of Service prohibit unauthorized access to the App and its systems, automated access, and circumventing security or rate-limiting controls. Research that follows this policy is authorized, so it is not a breach of those Terms, and we will not treat it as one. Provided you stay inside this policy: We will not bring, or support anyone else bringing, a legal claim against you arising from your research. We will not suspend or terminate your Supload account for it. If someone else brings a claim about research that followed this policy, we will make it known that the testing was authorized. We will treat your report as a good-faith one even if it turns out there is no vulnerability, or you break something by accident and tell us promptly. This authorization does not extend to activity outside this policy — reaching another person's data, degrading the service for others, extracting more data than is needed to demonstrate a finding, or anything in the OUT OF SCOPE list above. It does not authorize you to act against a third party's systems, and it does not change any other part of the Terms of Service. REWARDS Supload does not operate a paid bug bounty programme. We will credit reporters who ask to be credited, once a fix has shipped.