Security and Responsible Disclosure

Effective Date: August 13, 2026

Security and Responsible Disclosure

Found something?

Tell us.

We welcome good-faith reports that help make Spine Framework safer.

Reporting a Vulnerability

Send security reports to: security@spine-framework.com

Please include enough information for us to reproduce and understand the issue, including the affected component or URL, steps to reproduce it, expected and observed behavior, and any relevant proof of concept.

Please avoid sending sensitive data unless necessary to explain the vulnerability.

Good-Faith Research

When conducting security research against services we operate:

  • Do not intentionally disrupt availability.
  • Do not perform denial-of-service testing.
  • Do not use social engineering, phishing, or physical attacks.
  • Do not access more user data than necessary to demonstrate the issue.
  • Do not modify or delete other users' information.
  • Do not establish persistence.
  • Stop testing once you have demonstrated the vulnerability.
  • Give us reasonable time to investigate before publicly disclosing the issue.

What We Will Do

We will make reasonable efforts to acknowledge legitimate reports, investigate them, and communicate with researchers while the issue is being evaluated.

Spine Framework is an early release, and we do not promise that every report will result in a fix or that a fix will be available within a particular timeframe.

Safe Harbor

If you conduct research in good faith, comply with this Policy, and avoid privacy violations, service disruption, and unnecessary harm, we will not initiate legal action against you solely for that research.

If a third party initiates legal action related to research that complied with this Policy, we may confirm that the research was conducted under our responsible-disclosure program.

Bug Bounties

Unless we expressly announce otherwise, Spine Framework does not currently operate a paid bug-bounty program.

Reporting a vulnerability does not create a right to compensation.

Third-Party Systems

Do not test infrastructure owned by our vendors or other third parties unless their own policies expressly authorize it.

Contact

security@spine-framework.com