Security & Vulnerability Disclosure
We take the security of your pets' health data seriously. If you believe you've found a security vulnerability in Furbinder, we want to hear from you and will work with you to resolve it quickly.
How to report
Email security@furbinder.com with a description of the issue, the steps to reproduce it, and its potential impact. Please give us a reasonable time to investigate and fix the issue before any public disclosure. This inbox is monitored; machine details for automated tooling are in /.well-known/security.txt.
Scope
In scope:
- The Furbinder iOS and Android apps.
- Our API and Edge Functions (*.supabase.co endpoints we operate).
- The Furbinder website (furbinder.com).
Out of scope:
- Third-party services we depend on (report those to the provider).
- Reports from automated scanners without a demonstrated, exploitable impact.
- Social engineering, physical attacks, and denial-of-service testing.
- Missing best-practice headers with no concrete security impact.
Safe harbor
We will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy — provided you avoid privacy violations, data destruction, and service disruption, and only interact with accounts you own or have explicit permission to test. Do not access, modify, or delete other users' data.
Our commitment
- We acknowledge reports within 3 business days.
- We provide a triage assessment and severity within 10 business days.
- We keep you updated on remediation progress and credit you (with your permission) once resolved.
Furbinder does not currently run a paid bug-bounty program; we deeply appreciate responsible disclosure regardless.