Skip to content

Security

Vulnerability disclosure

Reporting a vulnerability

If you discover a security vulnerability in Entropy, disclose it responsibly by emailing security@entropy.com. We respond to all valid reports within 72 hours and aim to resolve confirmed vulnerabilities within 30 days.

Scope

In scope for disclosure:

  • entropy.com and all subdomains
  • The Entropy web application and API
  • Authentication and authorization logic
  • Data access and Firestore security rules
  • Cloud Functions endpoints

What we ask

  • Do not access or modify data that is not yours
  • Do not perform denial-of-service attacks
  • Do not disclose the issue publicly before we have resolved it
  • Act in good faith — we will do the same

Our commitment

We will not pursue legal action against researchers acting in good faith under this policy. We will acknowledge receipt of your report, keep you informed of our progress, and credit you in our acknowledgements unless you request otherwise.

Machine-readable: /.well-known/security.txt