Legal
Responsible disclosure.
How to report a vulnerability to Synq. The shortest path to a secure platform is the one where researchers can reach us quickly and confidently.
Report at security@aerosol.so
What to include
- · A description of the vulnerability and the affected surface (API endpoint, SDK, dashboard route).
- · Reproduction steps with as much detail as possible.
- · The impact you believe the issue has if exploited.
- · A name or handle if you would like public credit.
What we commit
- · Acknowledgement within one business day.
- · Status updates as the fix progresses, including a target patch date for confirmed issues.
- · Critical issues fixed within 14 days where possible.
- · Public credit on the release notes when you opt in.
What we ask
- · Do not exfiltrate user data or impact other users while testing.
- · Do not run mass scans or denial-of-service tests without explicit written approval.
- · Give us a reasonable window to fix before public disclosure (target: 90 days from acknowledgement).
Out of scope
Theoretical findings without practical demonstration, vulnerabilities in third-party software not under our control, missing security headers without demonstrated impact. We treat these as suggestions rather than reports and still appreciate the heads-up.
PGP key available on request — email security@aerosol.so.
Thank you, in advance.
Every researcher who reaches out helps make the platform safer for everyone who builds on it.
