Security Policy

Vulnerability Disclosure Policy

We take the security of uptimeify.io seriously. If you've found a vulnerability, we want to hear from you — and we commit to working with you to address it responsibly.

Our commitment

We will acknowledge receipt of your report within 72 hours and keep you informed as we investigate and remediate the issue. We will not take legal action against researchers who act in good faith and follow this policy.

We follow a 90-day responsible disclosure timeline — after 90 days, you are free to publish your findings regardless of our remediation status.

Scope
In scope
  • uptimeify.io (web app)
  • ping.uptimeify.io
  • Authentication & sessions
  • Authorization & access control
  • Data exposure / leaks
  • Injection vulnerabilities
  • Business logic flaws
Out of scope
  • Denial of service (DoS)
  • Social engineering of staff
  • Physical security
  • Third-party services
  • Issues in outdated browsers
  • Missing security headers only
  • Self-XSS
Disclosure process
Day 0
You submit a report to security@uptimeify.io. Please include reproduction steps, impact assessment, and any proof-of-concept.
Day 1–3
We acknowledge receipt and begin triage. We may contact you for additional details.
Day 4–30
We investigate, develop a fix, and keep you informed of our progress at regular intervals.
Day 30–90
We aim to remediate all confirmed vulnerabilities. Critical issues are prioritised and may be patched sooner.
Day 90
Coordinated public disclosure. We will credit you in our security acknowledgments unless you prefer anonymity.
Ground rules
  • Do not access, modify, or delete data belonging to other users
  • Do not perform actions that degrade service availability
  • Do not use automated scanners against production systems without prior approval
  • Do not disclose the vulnerability publicly before the 90-day window has passed
  • Act in good faith — demonstrate impact without exceeding what is necessary
Recognition

We currently do not offer a monetary bug bounty program. However, researchers who report valid, in-scope vulnerabilities will be recognised publicly on our Security Hall of Fame — unless they prefer to remain anonymous.

Report a vulnerability

Last updated: May 2026 · security.txt