Security Policy
If you believe you have found a security issue in CheckFast, email the security team with enough detail to reproduce and assess the impact. We review legitimate reports and prioritize issues that protect user data, billing state, authentication, monitoring integrity, and production availability.
security@checkfast.ioWhat to include
- Clear reproduction steps and affected URL, API route, or workflow.
- Observed impact and the account, monitor, report, or billing object involved.
- Any proof of concept that avoids destructive actions and avoids user data access.
Scope
In-scope reports include authentication and authorization bypasses, cross-tenant data exposure, SSRF, webhook spoofing, billing entitlement bypasses, stored or reflected XSS, and production availability risks. Please do not run destructive tests, spam users, access data that is not yours, or degrade the service.
Response
We aim to acknowledge actionable reports promptly, validate the affected boundary, patch the smallest safe surface, add regression coverage, and document any required operational mitigation. We may ask for additional evidence when a report is not reproducible from the information provided.