Skip to content
Legal

Responsible disclosure.

How to report a vulnerability to Synq. The shortest path to a secure platform is the one where researchers can reach us quickly and confidently.

Report at security@aerosol.so

What to include

  • · A description of the vulnerability and the affected surface (API endpoint, SDK, dashboard route).
  • · Reproduction steps with as much detail as possible.
  • · The impact you believe the issue has if exploited.
  • · A name or handle if you would like public credit.

What we commit

  • · Acknowledgement within one business day.
  • · Status updates as the fix progresses, including a target patch date for confirmed issues.
  • · Critical issues fixed within 14 days where possible.
  • · Public credit on the release notes when you opt in.

What we ask

  • · Do not exfiltrate user data or impact other users while testing.
  • · Do not run mass scans or denial-of-service tests without explicit written approval.
  • · Give us a reasonable window to fix before public disclosure (target: 90 days from acknowledgement).

Out of scope

Theoretical findings without practical demonstration, vulnerabilities in third-party software not under our control, missing security headers without demonstrated impact. We treat these as suggestions rather than reports and still appreciate the heads-up.

PGP key available on request — email security@aerosol.so.

Thank you, in advance.

Every researcher who reaches out helps make the platform safer for everyone who builds on it.