PerkSpringSecurityVDP

Vulnerability Disclosure Policy

PerkSpring welcomes security researchers to report vulnerabilities responsibly. We believe that working with skilled security researchers across the globe is crucial to identifying weaknesses in our systems. If you believe you have found a security vulnerability in any PerkSpring service, we encourage you to let us know right away.

Scope

This policy applies to the following PerkSpring services:

  • Production application: tryperkspring.com
  • All API endpoints served under the production domain

Out of Scope

The following are excluded from this policy:

  • Social engineering (e.g., phishing, vishing, smishing)
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
  • Third-party services used by PerkSpring, including Clerk and Neon

How to Report

Please email your findings to security@perkspring.com. Include the following in your report:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • An assessment of the potential impact

Safe Harbor

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized and will not pursue legal action related to your research.

Response Timeline

  • Acknowledgement: within 3 business days
  • Status update: within 10 business days

What We Ask

  • Do not access or modify other users' data
  • Do not degrade the availability of our services
  • Give us reasonable time to address the issue before any public disclosure