Vulnerability Disclosure Policy
Last updated: August 9, 2026
1. Introduction
SweepFeed values the security community and the important role researchers play in keeping our platform and users safe. We encourage responsible disclosure of security vulnerabilities and commit to working with researchers to address valid findings promptly.
2. Scope
The following assets are in scope for security research:
- sweepfeed.com — Main website and all subdomains
- SweepFeed mobile applications — iOS and Android apps if and when public mobile apps launch
- SweepFeed API — All API endpoints under sweepfeed.com/api/*
The following are out of scope:
- Third-party services and integrations (Google, Firebase, Stripe, Vercel, etc.)
- Denial of service (DoS/DDoS) attacks
- Social engineering or phishing attacks against SweepFeed employees or users
- Physical security of SweepFeed offices or data centers
- Vulnerabilities in third-party sweepstakes sponsor websites
- Reports based solely on automated scan output without a demonstrated exploit
3. Reporting a Vulnerability
If you believe you have discovered a security vulnerability, please report it to us as soon as possible:
- Email: security@sweepfeed.com
- Subject Line:"Security Vulnerability Report — [Brief Description]"
Please include in your report:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any proof-of-concept code, screenshots, or video recordings
- The affected URL(s), API endpoint(s), or app screen(s)
- Your name or handle (for credit, if desired)
4. Our Commitments
When you report a vulnerability in good faith, our current response targets are:
- Acknowledgment: normally within 3 business days
- Initial assessment: normally within 10 business days, when the report is reproducible
- Remediation: prioritized according to verified risk, exploitability, affected users, and the safety of the fix. We do not promise a fixed resolution date before assessing the report
- Communication: status updates when there is a material change or we need more information
- Credit: public acknowledgment may be offered with your permission after remediation
5. Safe Harbor
SweepFeed will not initiate or recommend legal action for research that is conducted in good faith, stays within this policy, and avoids harm, provided the researcher:
- Do not access, modify, or delete other users' data
- Do not disrupt or degrade the availability of the Service
- Do not publicly disclose the vulnerability before SweepFeed has had a reasonable opportunity to address it and coordinates disclosure timing with us
- Do not exploit any vulnerability beyond the minimum necessary to demonstrate it
- Do not use automated vulnerability scanners that generate excessive traffic
- Comply with all applicable laws
We consider research conducted consistently with this policy to be authorized by SweepFeed for the systems we control. We cannot authorize testing of third-party systems or waive rights belonging to another person. If a good-faith report is later found to fall outside this policy, contact us before continuing so we can evaluate a safe path.
6. Qualifying Vulnerabilities
The following types of vulnerabilities are of particular interest:
- Authentication or authorization bypasses
- Cross-site scripting (XSS) with demonstrated user impact
- Server-side request forgery (SSRF)
- SQL injection or NoSQL injection
- Remote code execution
- Insecure direct object references (IDOR) exposing user data
- Significant privacy violations (unauthorized access to PII)
- Payment bypass vulnerabilities
7. Exclusions
The following are generally not considered qualifying vulnerabilities:
- Missing security headers without demonstrated exploit
- Clickjacking on pages without sensitive actions
- CSRF on public pages or logout functionality
- Missing rate limiting on non-critical endpoints
- Outdated software versions without a known exploit chain
- Best practice recommendations without demonstrated vulnerability
- Reports from automated tools without manual verification
8. Rewards
SweepFeed does not currently operate a paid bug bounty program. However, we deeply appreciate the security community's contributions and may offer rewards at our discretion for particularly impactful findings. Public acknowledgment may be offered with the reporter's permission.
9. Contact
Security reports: security@sweepfeed.com
General inquiries: support@sweepfeed.com
Questions about this policy? Reach out at support@sweepfeed.com