Security

Security Policy

We welcome good-faith vulnerability reports. We do not pay bounties. Please email security@steadyhq.com with:


  • Description of the issue

  • Affected URLs/endpoints

  • Steps to reproduce

  • Expected vs actual behavior

  • Proof-of-concept (text only, no live exploits)

Scope

  • In-scope: steadyhq.com, steady.page, all subdomains we operate, our official apps, and our API.

  • Out-of-scope: third-party services, social accounts, physical offices, spam, social engineering.

  • Common exclusions: clickjacking on non-sensitive pages, missing security headers, rate-limiting/brute-force without real impact, SSL/TLS best-practice warnings.

Rules of Engagement

  • No DoS, stress tests, or automated scans beyond normal rate limits.

  • Do not access, modify, or exfiltrate data that isn’t yours. Use test data only.

  • Test only accounts you own or have explicit permission for.

  • Stop immediately if you encounter sensitive data and report privately.

Safe Harbor

We will not pursue legal action for good-faith testing and disclosure that follows this policy.