Skip to content

Security: ZihangDong/24picture

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in 24Picture, please report it responsibly.

Do not open a public issue. Instead, email us at:

security@toolknit.com

We will respond within 48 hours and work with you to address the issue promptly.

Scope

The following areas are in scope:

  • Cross-Site Scripting (XSS) vulnerabilities
  • Client-side data exposure issues
  • Service Worker security concerns
  • API endpoint vulnerabilities

Out of Scope

  • Issues that require physical access to a user's device
  • Social engineering attacks
  • Denial of service via excessive tool usage (all processing is client-side)

Safe Harbor

We will not pursue legal action against anyone who:

  • Makes a good faith effort to avoid privacy violations and data destruction
  • Provides us reasonable time to fix the issue before public disclosure
  • Does not exploit the vulnerability beyond what is necessary to demonstrate it

Thank you for helping keep 24Picture secure.

There aren't any published security advisories