Vulnerability Disclosure Policy
Last updated: October 4, 2026
Basepoint Labs, Inc. welcomes reports from security researchers and customers who find a vulnerability in Basepoint. This policy explains what is in scope, how to report, the rules we ask you to follow, and what we commit to in return.
1. How to report
Email hello@getbasepoint.com with the subject line "Security report". Include the affected URL or component, steps to reproduce, the impact as you understand it, and any proof-of-concept material. If you would like credit, say so and tell us the name to use. The same contact is published in our security.txt.
2. Scope
In scope:
- The web application at dashboard.getbasepoint.com and its APIs.
- The client portal and share links issued by the application.
- This website, getbasepoint.com.
Out of scope:
- Services run by our providers (for example Vercel, Supabase, AWS, Anthropic, OpenAI, Stripe). Report those to the provider.
- Denial of service, resource exhaustion, or anything that degrades the service for other users.
- Social engineering of Basepoint staff or customers, and physical attacks.
- Findings from automated scanners with no demonstrated impact, missing best-practice headers without an exploit, and reports about software versions alone.
- Issues that require a compromised device or account to begin with.
3. Rules for testing
- Test only against accounts and data you own or are authorized to use. Do not access, modify, or delete other customers' data. If you encounter it by accident, stop, record only what is needed to show the issue, and tell us.
- Do not disrupt the service. No load testing, no brute forcing, no spam.
- Do not exfiltrate data beyond the minimum needed to demonstrate the finding, and delete it once the report is acknowledged.
- Give us a reasonable time to fix the issue before disclosing it publicly. We will agree a timeline with you and will not ask for silence beyond what the fix needs.
4. What we commit to
- We aim to acknowledge every report within three business days.
- We will tell you what we found, keep you updated while we fix it, and let you know when it is resolved.
- We will credit you on request once the issue is fixed.
- We will not pursue legal action against researchers who act in good faith under this policy, and we will not report you to law enforcement for good-faith research. If a third party brings a claim, we will make clear that your actions were authorized under this policy.
5. Rewards
We do not currently run a paid bug bounty programme. We do credit researchers publicly on request, and we will say thank you properly.
6. Changes
We may update this policy as the programme matures. The date at the top shows the latest revision.
