Found something? Tell us.
Email [email protected] with what you found, the URL or request that shows it, and what an attacker could do with it. The same address is published at /.well-known/security.txt.
What happens after you send it
- We acknowledge the report within three working days.
- We tell you whether we can reproduce it, and what we intend to do, within ten working days.
- We tell you when the fix ships. If we decide not to fix something, we say that and why rather than going quiet.
- We will credit you by name on request once the fix is out. We will not name you without asking.
There is no paid bounty
We do not run a bug bounty and we do not pay for reports. That is not a comment on the value of the work — it is a small company being straight with you about what it can offer, so nobody spends a weekend on this expecting a cheque.
What you may test
Our own accounts and our own demo studio, on the marketing site, the demo storefront and the checkout that belongs to it. Please do not test against a real studio's storefront or a real customer's booking: the rooms, the money and the calendar behind them belong to somebody running a business.
- No denial of service, load testing or traffic floods.
- No social engineering of studio staff, our staff, or anyone's payment processor.
- No physical access attempts, and nothing aimed at a third party we depend on — report those to them.
- Stop at the first proof. Do not read, change, move or keep anyone else's data, and tell us if you reach data that is not yours by accident.
Testing inside those lines is something we asked for, and we will not pursue a report made in good faith that stayed inside them.
What we do not claim
We hold no SOC 2 report and no ISO 27001 certificate. Card details are handled by the studio's payment processor and never reach our servers — the detail is on the PCI scope page. What we store and who we pass it to is on the privacy page.