Security and Responsible Disclosure
Effective 2026-08-08
Pilot safeguards
- Tenant-bound hostname and membership checks on every application and sync request.
- PostgreSQL row-level security and least-privilege runtime, resolver, and replication roles.
- Secure, HTTP-only, same-site session cookies and verified email for production accounts.
- Encrypted provider transport, managed storage encryption, structured audit events, backups, and health monitoring.
- Secrets kept outside source code and container images.
Report a vulnerability
Email security@cinchme.app with the affected URL, impact, reproduction steps, and a safe proof of concept. Do not access another person’s data, disrupt service, use social engineering, or run destructive/high-volume tests. Give us reasonable time to investigate before disclosure.
Response
We will acknowledge reports as promptly as practical, preserve confidentiality, share status when possible, and credit reporters who request it. This pilot does not yet offer a paid bug bounty.