Security
How to report a vulnerability in VoidPort.
Last updated September 27, 2026
Reporting a vulnerability
Email security@voidport.app. Please include:
- What is affected (website, API, CLI, relay) and the version if known
- Steps to reproduce, or a proof of concept
- The impact you expect
- How we can reach you, and whether you want to be credited
We acknowledge reports within 3 business days and keep you updated until the issue is fixed. Please give us reasonable time to fix it before you publish anything.
Safe harbor
We will not take legal action against good-faith research that follows this policy. Stay within these limits: don't access or change other people's data beyond what you need to show the issue, don't destroy data, and don't disrupt the service for others.
Out of scope
- Denial of service and volumetric or load tests
- Social engineering and phishing of our staff or users
- Content served through customer tunnels. Please use Report abuse instead.
- Automated scanner findings without a demonstrated impact
Rewards
We don't run a paid bug bounty at the moment. We're happy to credit you for a valid report.