We welcome responsible disclosure of security vulnerabilities through our coordinated program.
Research must be conducted on our main domain and related subdomains only.
Researchers must not access, modify, or delete user data during their investigation.
DDoS, brute-force, and social engineering attacks are strictly prohibited.
We commit to acknowledging all valid reports within 48 hours and fixing issues promptly.
We provide "Safe Harbor" and will not take legal action against researchers acting in good faith.
For all security inquiries and vulnerability reports, please contact: vybex.signal@gmail.com
Last updated: July 21, 2026