Security
Report suspected security vulnerabilities privately so we can investigate before details become public.
Security disclosure policy
Report a vulnerability
Email your findings to security@chief.app. If you want to encrypt the message, use the PGP key linked from our security.txt file.
What to include
Give us enough information to reproduce and assess the issue:
- a clear description of the vulnerability;
- the affected Chief Tools application, page, or component;
- the steps needed to reproduce it;
- relevant screenshots or proof-of-concept code;
- contact details if you want us to follow up with questions.
Remove personal data and secrets that are not needed to demonstrate the problem.
What happens after you report it
We will acknowledge your report within five business days. We will investigate the report and work to fix confirmed vulnerabilities. When possible, we will keep you informed about our progress.
Please allow reasonable time for us to investigate and address the issue before publishing details.
Rules for security research
You may investigate Chief Tools systems in good faith, provided that you:
- access only accounts, teams, and data that belong to you or that you have permission to test;
- avoid changing or deleting anyone else's data;
- do not disrupt or degrade our services;
- keep automated scanning at a reasonable rate;
- stop and contact us if your research exposes private data or could affect other users.
Safe harbour
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith while following this policy.
No bug bounty
We do not offer rewards
Chief Tools does not operate a bug bounty or reward program. Reports are voluntary, and we cannot offer payment or other compensation.