Report a vulnerability
If you think you have found a security problem in Standby, we want to hear about it.
How to report
Email Kirimitosa@gmail.com with a short description of the problem, the page or endpoint involved, and the steps to reproduce it. Screenshots or a proof of concept help. Please keep the details private until we have had a chance to fix it.
Our contact details are also published in security.txt.
Please do
- Test only with accounts you created yourself.
- Stop as soon as you have shown the problem exists.
- Tell us if you came across anyone else's personal data, and delete it.
Please do not
- Access, change or delete other people's accounts, messages or payments.
- Run denial of service tests, spam, or automated scans that degrade the site.
- Use social engineering against our users or staff.
- Make real payments as part of testing.
What to expect
Standby is a small team. We read every message, usually within 2 business days. We cannot guarantee a response time. We do not run a bug bounty program and cannot promise payment.