Security and Responsible Disclosure
Last updated: October 2, 2026
Keeping PromoVote and the people who trust us safe matters to us. If you find a security vulnerability, please tell us privately so we can fix it. We welcome reports from the security community and will work with you in good faith.
1. How to report
Email security@promovote.com with:
- A description of the issue and the impact you think it has.
- The URL or component affected.
- Clear steps to reproduce, and a proof of concept if you have one.
- How you would like to be credited, if at all.
Please write in English. Do not include personal data of other people in your report. Our security contact details are also published in our security.txt file.
2. Scope
In scope:
- promovote.com and www.promovote.com
- The waitlist form and its API
Out of scope:
- Third-party services we use, such as Cloudflare. Please report issues in those services directly to the provider.
- Denial of service or load testing.
- Social engineering, phishing, or physical attacks against our team or providers.
- Spam or automated sign ups to the waitlist.
- Reports from automated scanners without a demonstrated, real impact.
- Missing security headers or best practices with no clear security impact, clickjacking on pages with no sensitive actions, and self-XSS.
3. Rules for testing
- Only test against accounts or data you own. Do not access, change or delete other people's data. If you accidentally access personal data, stop, do not keep a copy, and tell us right away.
- Do not degrade or interrupt the service for others.
- Do not try to get around the bot check at scale or flood the waitlist.
- Give us reasonable time to fix the issue before sharing it publicly. We ask for 90 days, or less if we agree a fix is already live.
- Do not ask for payment in exchange for not disclosing a vulnerability.
4. Safe harbor
If you make a good faith effort to follow this policy, we will consider your research authorized, we will not take legal action against you or ask law enforcement to investigate you for it, and we will not pursue claims under laws such as the US Computer Fraud and Abuse Act or anti-circumvention rules for that research. If a third party takes legal action against you for research done under this policy, we will make it known that your actions were authorized by us. This safe harbor does not cover actions that harm users, violate privacy, disrupt the service, or break the law in other ways.
5. What to expect from us
- We aim to confirm we received your report within 5 business days.
- We will keep you informed as we investigate and fix the issue.
- We will let you know when it is fixed and, if you want, credit you publicly.
PromoVote is a small, early stage team, so response times may vary. We will always reply.
6. Rewards
We do not run a paid bug bounty program at this time. We are grateful for every valid report and are happy to give public credit.