Policies / Security and Vulnerability Disclosure
Security and Vulnerability Disclosure
Effective: [EFFECTIVE DATE]
If you find a security weakness in 24 Frames, we want to hear about it and fix it before anyone gets hurt. This page says how to report a problem, what we ask of you while you look, and what we promise in return. The short version: email [SECURITY CONTACT EMAIL], do not touch other people's data, give us time to fix it, and we will thank you.
How to report
Email [SECURITY CONTACT EMAIL] with what you found and where (URL, endpoint, app screen or version), the steps to reproduce it, what an attacker could do with it, and whether you want to be credited and under what name. We will acknowledge your email within five working days.
What we ask of you
- Do not take data that is not yours. If you can see other people's information, stop, note how you got there and tell us. Do not download, copy or share it.
- Do not disrupt the service. No denial-of-service testing, no flooding, no deleting or changing content that belongs to others.
- Do not use social engineering, phishing or physical attacks against our staff, our gateway phones or our office.
- Test only accounts you own.
- Give us reasonable time to fix the problem before talking about it publicly. We aim for 90 days from acknowledgement and will tell you if we need longer.
- Follow the law. Nothing here permits you to break it.
What we promise
- We will acknowledge your report, investigate it and keep you informed.
- We will fix real problems as quickly as their severity demands.
- We will credit you, if you want, once the fix is live.
- We will not take legal action against you for research carried out in good faith within these rules.
- We do not run a paid bounty programme at this time.
In scope
- The API at api.24frames.co
- The website and creator studio at 24frames.co
- The staff console at admin.24frames.co
- The 24 Frames viewer app
- The internal SMS gateway app, as far as it can be reached from outside
Out of scope
- Social engineering, phishing and physical intrusion
- Denial-of-service or volume-based attacks
- Third-party services we use (Bunny CDN, Resend, mobile network operators, app stores); report those to the provider
- Automated scanner output with no demonstrated impact
- Missing best-practice headers or settings with no exploitable effect
- Attacks that need a stolen or rooted device
If you are a user, not a researcher
If you think someone else has used your account, revoke your devices under "Your devices" in the app and email [SUPPORT EMAIL]. To see how we protect your information day to day, read section 10 of the Privacy Policy.
Contact
- Security reports: [SECURITY CONTACT EMAIL]
- Everything else: [SUPPORT EMAIL]