Skip to content
Documentation menu

Vulnerability disclosure policy

How to test carefully, report security issues privately, and coordinate remediation with Itemra.

Pre-launch activation notice: security@itemra.io is the intended private reporting address. The mailbox, helpdesk routing, monitoring, and final counsel review must be activated before this policy is published in production. Repository and prerendered artifacts are not evidence that the reporting route is live.

Report a security issue privately

When the contact is activated, send a concise report to security@itemra.io. Do not send passwords, API keys, session tokens, private keys, or unnecessary personal/customer data. Include:

  • the affected Itemra origin, route, or component;
  • a clear description and the security impact;
  • minimal, reproducible steps using accounts and data you control;
  • relevant timestamps and sanitized request/response evidence; and
  • a safe way to contact you about remediation and coordinated disclosure.

If sensitive proof is required, first ask for an approved encrypted transfer method. Do not attach a production database export or broad automated scan.

Scope

The intended scope is Itemra-controlled application behavior on itemra.io, docs.itemra.io, app.itemra.io, and api.itemra.io after those origins are publicly activated. Only test organizations, accounts, records, API keys, webhook receivers, and files you own or are explicitly authorized to use.

Third-party services and infrastructure, including WorkOS, Stripe, SendGrid, Azure, GitHub, DNS/registrar services, and their personnel, are outside this authorization. Report a third-party issue under that provider's policy unless the issue is caused by Itemra's integration behavior.

Research rules

  • Avoid privacy violations, data access beyond your test data, persistence in another user's account, and any destructive change.
  • Do not perform denial of service, load testing, spam, social engineering, physical intrusion, malware deployment, credential stuffing, or broad automated scanning.
  • Stop when you encounter data that is not yours. Record the minimum evidence, do not copy it, and report immediately.
  • Do not exploit an issue beyond the minimum needed to demonstrate impact.
  • Do not publicly disclose an unresolved issue before Itemra has had a reasonable opportunity to investigate and remediate it.
  • Comply with applicable law and this policy. This policy cannot authorize activity against a third party.

Safe-harbor intent — counsel approval pending

For good-faith research that follows this policy, Itemra intends to treat the work as authorized security research and not initiate legal action solely because you tested and reported the issue. If we believe your activity falls outside this policy, we intend to contact you and ask you to stop before taking further action where circumstances permit.

This statement does not waive third-party rights, authorize access to data or systems you do not control, or promise immunity from applicable law. The final safe-harbor wording requires counsel approval before production activation.

Response expectations

After mailbox/helpdesk activation, Itemra's operating targets are:

  • acknowledge a complete report within three business days;
  • provide an initial severity/triage response within ten business days;
  • send a status update at least every ten business days while remediation is active; and
  • coordinate a disclosure date after remediation, normally aiming for no more than 90 days unless exploitation risk, customer safety, or a dependency requires a different plan.

These are good-faith response targets, not a contractual support SLA or a promise that every report is a vulnerability. Duplicate, spam, incomplete, or out-of-scope submissions may receive a shorter response.

Recognition and rewards

Itemra does not currently operate a bug-bounty or guaranteed public acknowledgment program. Do not incur cost or expect payment without a separate written agreement. We will coordinate any optional credit with the reporter and will not publish a name or report without permission.