Security & Vulnerability Disclosure Policy
Last updated: 23/08/2026
1. Our Commitment
We take the security of the DockSpare Platform seriously and welcome reports from security researchers who find a genuine vulnerability. This policy tells you how to report one, and what to expect from us in return.
2. Scope
This policy covers the DockSpare web application at dockspare.netlify.app and its backend (authentication, database access controls, and the platform's Edge Functions). If you're unsure whether something is in scope, ask us before testing it.
3. Out of Scope
- Denial-of-service testing, or anything that could degrade the Platform for real users;
- Social engineering, phishing, or physical attacks against DockSpare staff or users;
- Automated scanning that generates significant traffic without prior coordination with us;
- Vulnerabilities in third-party services we rely on (Supabase, Netlify, Cloudflare) — please report those directly to the relevant provider;
- Issues that require an unlikely degree of user interaction or an already-compromised device to exploit.
4. How to Report
Email the details to the address below. Please do not disclose the issue publicly, and do not access, modify, or delete data belonging to other users beyond what's strictly necessary to demonstrate the issue (for example, prove access exists, don't extract the data itself).
5. What to Include
- A clear description of the vulnerability and its potential impact;
- Steps to reproduce it (URLs, requests, screenshots, or a proof-of-concept);
- The account or test data you used, if relevant, so we can distinguish your testing from a real incident;
- Your contact details, so we can follow up with questions or updates.
6. Our Response Process
We aim to acknowledge a valid report within a reasonable time and keep you informed as we investigate and fix the issue. Given DockSpare's current size, we do not run a paid bug bounty program, but we're happy to credit researchers publicly (with permission) for a valid, responsibly disclosed report.
7. Safe Harbor
We will not pursue legal action against a researcher for good-faith testing that:
- Stays within the scope defined above;
- Avoids privacy violations, service disruption, and destruction of data;
- Is reported to us promptly and not disclosed publicly before we've had a reasonable chance to address it.
This safe harbor does not extend to testing that falls outside these conditions.
8. Contact
Security reports can be sent to security@dockspare.example.