Security and Responsible Disclosure

Last updated: October 2, 2026

Keeping PromoVote and the people who trust us safe matters to us. If you find a security vulnerability, please tell us privately so we can fix it. We welcome reports from the security community and will work with you in good faith.

1. How to report

Email security@promovote.com with:

Please write in English. Do not include personal data of other people in your report. Our security contact details are also published in our security.txt file.

2. Scope

In scope:

Out of scope:

3. Rules for testing

4. Safe harbor

If you make a good faith effort to follow this policy, we will consider your research authorized, we will not take legal action against you or ask law enforcement to investigate you for it, and we will not pursue claims under laws such as the US Computer Fraud and Abuse Act or anti-circumvention rules for that research. If a third party takes legal action against you for research done under this policy, we will make it known that your actions were authorized by us. This safe harbor does not cover actions that harm users, violate privacy, disrupt the service, or break the law in other ways.

5. What to expect from us

PromoVote is a small, early stage team, so response times may vary. We will always reply.

6. Rewards

We do not run a paid bug bounty program at this time. We are grateful for every valid report and are happy to give public credit.