Security
Last updated: June 2026
We take security seriously and welcome reports from the security research community. If you believe you've found a vulnerability in Sandpaw, please tell us about it — we want to fix it.
How to report a vulnerability
Email [email protected] with:
- A clear description of the issue.
- Steps to reproduce — ideally with a minimal proof-of-concept.
- The impact you believe it has.
- Any logs, screenshots, or URLs that help us triage faster.
PGP and signed mail are welcome but not required. We'll acknowledge from a real person at the address above.
Scope
The following are in scope for this policy:
sandpaw.ai— marketing site, signup flow, login, admin, billing, and API surfaces.*.sandpaw.ai— per-customer instance subdomains, including the Control UI and Gateway.
Out of scope
- Volumetric / network DDoS (mitigated at the edge — please do not test against production).
- Social engineering of Sandpaw team members, contractors, or customers.
- Physical access to our hosting facilities or hardware.
- Vulnerabilities in third-party services we depend on (Anthropic, Stripe, Resend, Cloudflare, Hetzner). Please report those to the relevant vendor.
- Findings from automated scanners with no demonstrated exploit path.
- Missing best-practice security headers without a concrete attack scenario.
- Self-XSS, clickjacking on pages without sensitive actions, and other low-severity issues without realistic impact.
Response SLA
- Acknowledgement: within 72 hours of receipt.
- Triage update: within 7 days, with our assessment of severity and a rough remediation timeline.
- Fix and disclosure: coordinated with the reporter. We aim for fixes within 30 days for high-severity issues and 90 days for medium-severity, faster when the impact warrants it.
Recognition
We maintain a hall of fame for researchers who help us improve Sandpaw's security. There is no monetary bounty at this time — Sandpaw is early-stage and the surface area is still moving. We're committed to standing up a real bug bounty program once the platform is more stable, and we'll honor in-scope reports filed in good faith before that program exists when we set it up.
Safe harbor
Good-faith security research is welcome. We will not:
- Pursue legal action against researchers who report vulnerabilities in accordance with this policy.
- Treat research that stays within scope, avoids access to data that isn't yours, and respects user privacy as unauthorized under the CFAA or analogous laws.
In return, we ask that you:
- Give us a reasonable window to fix the issue before public disclosure.
- Avoid privacy violations, data destruction, service interruptions, and degradation of customer experience.
- Don't access, modify, or download more data than necessary to demonstrate the issue.
- Stop and contact us if you encounter customer data during testing.