Skip to content

Security: toppp-ai/.github

Security

SECURITY.md

Security Policy

Toppp handles customer sales conversations, so we take reports about our systems seriously. If you believe you have found a vulnerability, please tell us before you tell anyone else.

Scope

In scope:

  • toppp.ai and everything served under it
  • The Toppp web application and its APIs
  • Any Toppp library or embeddable component we have published, in this organisation or on npm

Out of scope:

  • Findings that require physical access to a user's device, or a compromised browser
  • Reports produced only by an automated scanner, with no demonstrated impact
  • Missing hardening headers or best-practice suggestions with no exploitable consequence
  • Social engineering of Toppp staff or customers
  • Denial of service, load testing, or any test that degrades service for real users

Reporting a vulnerability

Email business@toppp.ai with SECURITY in the subject line.

Please include:

  1. The affected domain, URL or endpoint
  2. What the issue is, and what an attacker could do with it
  3. Reproduction steps, or a minimal proof of concept
  4. Anything that helps us reproduce it — request/response captures, screenshots, timestamps

If you need to send something sensitive, say so in your first email and we will arrange an encrypted channel.

Please do not open a public GitHub issue or disclose the finding publicly before we have had a chance to fix it.

What happens next

We answer every report. We do not publish a fixed response window, but this is the sequence you can expect:

  • We confirm we have received it
  • We tell you whether we can reproduce it, and what we intend to do
  • We keep you updated while we work on a fix, and let you know when it ships
  • With your permission, we credit you once the fix is live

Safe harbour

We will not pursue legal action against you for security research carried out in good faith under this policy, provided you:

  • Stay within the scope above
  • Do not access, modify or retain data that is not your own — if you encounter customer data, stop and tell us immediately
  • Do not degrade or disrupt the service for other users
  • Give us reasonable time to remediate before any public disclosure

We do not currently run a paid bug bounty programme.

There aren't any published security advisories