Skip to content

Report a security vulnerability

Do not open a public GitHub issue or share exploit details publicly. Email support@vocapi.app with the subject “Vocapi security vulnerability report”. Include:

  • The affected product, URL, app version, device, or environment.
  • A description of the vulnerability and its potential impact.
  • Minimal steps to reproduce it or a proof of concept.
  • Whether you observed another person’s data or signs of active exploitation.
  • An optional suggested fix and your preferred contact or credit details.

Remove passwords, access tokens, API keys, personal data, and real user data from logs, screenshots, and examples. If sensitive material is essential, describe what you need to share instead of attaching it to the initial email.

Test only accounts, data, and devices you own or have explicit permission to use. Do not access, change, download, retain, or share another person’s data; disrupt service or destroy data; use social engineering or physical attacks; conduct denial-of-service or high-volume automated testing; or test third-party services under this policy. Follow each provider’s own disclosure policy. Stop testing and report promptly if you encounter credentials, secrets, or another person’s data.

We review reports based on impact and exploitability and coordinate validation, remediation, and disclosure when appropriate. Timing depends on the issue; we do not promise a particular acknowledgement, remediation, or disclosure deadline. This is not a bug bounty or payment program. It does not grant legal authorization or immunity, and it does not promise public credit.