In scope
- tailroster.com (marketing site)
- app.tailroster.com (the TailRoster application)
- api.tailroster.com (the public API)
Trust Center · Disclosure
We welcome security research conducted in good faith. This policy tells you what's in scope, how fast we respond, and the safe-harbor terms that protect you when you follow it.
Revision
Email security@tailroster.com with a clear description, reproduction steps, and the impact. PGP is available on request.
In scope
Out of scope
Severity classes
Our SLAs
Patterned on the disclose.io framework. If you make a good-faith effort to follow this policy:
A funded cash bounty is not live yet — we don't advertise payouts we don't pay. Today, every researcher who reports a valid issue in good faith is credited in this hall of fame (with your consent) and gets a genuine thank-you from the team. When we fund a paid program, the critical / high / medium / low tiers will be published here.
No one's here yet — this list is empty because we credit only real, verified reports and haven't received one. Be the first: email security@tailroster.com.
See also /.well-known/security.txt · Last revised