Back to Security
Responsible Disclosure

Security Vulnerability Disclosure

We appreciate security researchers who help keep diffray secure. This policy outlines how to report vulnerabilities and what to expect.

Scope

diffray.ai and app.diffray.ai domains
diffray GitHub App
API endpoints

Rules of Engagement

Do not publicly disclose vulnerabilities before they are fixed
Do not access or modify data belonging to other users
Do not perform denial-of-service attacks
Do not use automated scanning tools that generate excessive traffic
Act in good faith to avoid privacy violations and service disruption

Disclosure Process

1.

Submit Report

Send your findings to security@diffray.ai

2.

Acknowledgment

We'll confirm receipt within 48 hours

3.

Initial Assessment

We'll provide an initial evaluation within 5 business days

4.

Fix Critical Issues

Critical vulnerabilities addressed within 30 days

5.

Public Disclosure

Coordinated disclosure timeline agreed upon together

What to Include in Your Report

  • Detailed description of the vulnerability
  • Step-by-step reproduction instructions
  • Potential impact assessment
  • Suggested remediation (optional)
  • Your contact information for follow-up

Out of Scope

  • Social engineering attacks against employees
  • Physical security issues
  • Third-party services (AWS, GitHub, Anthropic)
  • Rate limiting issues without demonstrated impact
  • Missing security headers without proven exploitability
  • Vulnerabilities in outdated browsers or plugins
  • Reports from automated scanning tools without verified impact

Recognition

We appreciate security researchers who help keep diffray secure. With your permission, we'll acknowledge your contribution on this page.

Security Hall of Fame

Be the first to help secure diffray!

Report a Vulnerability

If you've discovered a security issue, please report it responsibly.

security@diffray.ai

PGP key available upon request