Security
Security Policy
We welcome good-faith vulnerability reports. We do not pay bounties. Please email security@steadyhq.com with:
Description of the issue
Affected URLs/endpoints
Steps to reproduce
Expected vs actual behavior
Proof-of-concept (text only, no live exploits)
Scope
In-scope: steadyhq.com, steady.page, all subdomains we operate, our official apps, and our API.
Out-of-scope: third-party services, social accounts, physical offices, spam, social engineering.
Common exclusions: clickjacking on non-sensitive pages, missing security headers, rate-limiting/brute-force without real impact, SSL/TLS best-practice warnings.
Rules of Engagement
No DoS, stress tests, or automated scans beyond normal rate limits.
Do not access, modify, or exfiltrate data that isn’t yours. Use test data only.
Test only accounts you own or have explicit permission for.
Stop immediately if you encounter sensitive data and report privately.
Safe Harbor
We will not pursue legal action for good-faith testing and disclosure that follows this policy.