Security
Vulnerability disclosure
Reporting a vulnerability
If you discover a security vulnerability in Entropy, disclose it responsibly by emailing security@entropy.com. We respond to all valid reports within 72 hours and aim to resolve confirmed vulnerabilities within 30 days.
Scope
In scope for disclosure:
- ▸entropy.com and all subdomains
- ▸The Entropy web application and API
- ▸Authentication and authorization logic
- ▸Data access and Firestore security rules
- ▸Cloud Functions endpoints
What we ask
- ▸Do not access or modify data that is not yours
- ▸Do not perform denial-of-service attacks
- ▸Do not disclose the issue publicly before we have resolved it
- ▸Act in good faith — we will do the same
Our commitment
We will not pursue legal action against researchers acting in good faith under this policy. We will acknowledge receipt of your report, keep you informed of our progress, and credit you in our acknowledgements unless you request otherwise.
Machine-readable: /.well-known/security.txt