Security

Report a security issue

If you have found a vulnerability in Supload, we want to hear about it. This page is the plain-language version of our coordinated vulnerability disclosure policy.

Where to report

Email [email protected]. Please include the affected URL, endpoint or app version, the steps needed to reproduce the issue, and what you believe an attacker gains from it.

This is the same address published in oursecurity.txtrecord. The canonical policy text lives at/.well-known/disclosure-policy.txt.

What happens next

Supload is a small team, so these are the targets we believe we can actually meet rather than a contractual service level:

  • We aim to acknowledge your report within 3 business days, at the address you write from.
  • We aim to give you a first assessment — whether we can reproduce it, and how we are rating it — within 10 business days.
  • We will tell you when the issue is fixed.

If one of those slips, please write again rather than assuming the report was ignored.

What is in scope

  • sup-load.com — this marketing and legal site.
  • portals.sup-load.com — the customer billing and account portal.
  • The Supload iOS application.
  • The Supabase backend those three use.

What is out of scope

  • Third-party platforms and their own infrastructure — Stripe, Supabase, Apple, Google, Microsoft, Dropbox and Cloudflare. Report those to the vendor.
  • Your own connected cloud storage account (Google Drive, Dropbox or OneDrive) and how that provider handles it.
  • Findings that require physical possession of an unlocked device, or a compromised operating system.
  • Social engineering of Supload staff, customers or vendors.
  • Denial of service, volumetric testing, and automated scanning against production.
  • Reports consisting only of scanner output with no demonstrated impact.

What we ask

  • Access, modify and retain only data belonging to an account you control.
  • Stop as soon as you have established that a vulnerability exists. Do not pivot, escalate, or enumerate other customers’ data to size the impact.
  • Do not degrade the service for other users.
  • Give us a reasonable opportunity to remediate before publishing.

Authorization and safe harbour

Security research carried out inside the scope and the rules above isauthorized by Supload LLC. OurTerms of Service prohibit unauthorized access to the App and its systems, automated access, and circumventing security or rate-limiting controls. Research that follows this policy is authorized, so it is not a breach of those Terms, and we will not treat it as one.

Provided you stay inside this policy:

  • We will not bring, or support anyone else bringing, a legal claim against you arising from your research.
  • We will not suspend or terminate your Supload account for it.
  • If someone else brings a claim about research that followed this policy, we will make it known that the testing was authorized.
  • We will treat your report as a good-faith one even if it turns out there is no vulnerability, or you break something by accident and tell us promptly.

This authorization does not extend to activity outside this policy — reaching another person’s data, degrading the service for others, extracting more data than is needed to demonstrate a finding, or anything in the out-of-scope list above. It does not authorize you to act against a third party’s systems, and it does not change any other part of the Terms of Service.

Rewards

Supload does not operate a paid bug bounty programme. We will credit reporters who ask to be credited, once a fix has shipped.

Not a security issue?

For product help use Support or[email protected]. For privacy and data requests use [email protected], which is also the address named in the Privacy Policy.

Join Waitlist