If you have found a security vulnerability, tell us: we are grateful to researchers acting in good faith and will not pursue legal action over reports that follow this policy.
Report to: security@praxtify.com
1. In Scope
praxtify.comand its subdomainsapp.praxtify.com(the application)- The Praxtify public API and webhook endpoints
2. Out of Scope
- Social engineering, phishing, physical attacks.
- Denial of service (DoS/DDoS), brute force and load testing.
- Vulnerabilities in third-party services (Supabase, Vercel, Stripe, Meta and the like) — report those to the provider directly.
- Automated scanner output submitted without demonstrated impact.
- Findings that are not exploitable on their own, such as missing security headers, version disclosure or SPF/DMARC configuration.
- Anything requiring unauthorized access to another person's account, data or infrastructure.
3. Rules
- Test only with your own account and your own data; do not access, modify or delete anyone else's data.
- If you gain access, stop at the minimum needed to demonstrate the issue and share the evidence with us.
- If you encounter personal data, stop immediately and say so in the report; do not retain or share it.
- Do not disclose the issue to third parties until it is fixed.
- Do not disrupt the service.
4. Safe Harbour
We will not initiate legal action over good-faith research that follows this policy, and if a third party does, we will state that you complied with it. Conduct outside this policy removes that protection.
5. Our Response Times
| Stage | Time |
|---|---|
| First response | Within 3 business days |
| Validation and severity | Within 10 business days |
| Fix target (critical) | 30 days |
| Fix target (other) | 90 days |
After a fix ships we are happy to credit you on this page if you wish. We do not run a paid bug bounty program today.
6. What to İnclude
- The affected address or endpoint.
- Step-by-step reproduction and a short description of the impact.
- Screenshots, a request/response sample or a proof of concept, if available.
- How we should contact you.
7. security.txt
This page is advertised in /.well-known/security.txt in line with RFC 9116.
8. About Product Security
How data is protected (encryption, tenant separation, access control, backups) is summarized in Section 4 of the Data Processing Agreement. Breach notification is in Section 7 of the same agreement.

