Reporting a security issue
How to report
If you believe you have found a security weakness in ApprUmp — the web app, the mobile app, or the way we handle your data — please email support@apprump.com with the subject line Security report. Tell us what you found, how to reproduce it, and what you think the impact is. Screenshots and request/response details help.
The same address and this policy are published in machine-readable form at /.well-known/security.txt (RFC 9116).
What you can expect from us
- An acknowledgement within three business days of your report reaching the mailbox above.
- An honest assessment of the issue, and a fix or mitigation on a timeline we will share with you. We will tell you when it is resolved.
- Credit, if you would like it, once the issue is fixed. Please say whether you want to be named.
- No legal action against you for research carried out in good faith within the guidelines below.
We are a small company. We do not run a bug-bounty programme and cannot promise a reward, but we do promise to take every report seriously and to answer it.
What we ask of you
- Give us a reasonable time to fix the issue before you talk about it publicly.
- Do not access, change, or delete data that is not yours. If you come across someone else's data while testing, stop and tell us — do not copy it.
- Do not run denial-of-service tests, spam, phishing, or social engineering against our people or our users.
- Test only against accounts you own; never against another customer's organization.
Scope
In scope: apprump.com and its subdomains, the ApprUmp mobile apps, and the API they use.
Out of scope: our third-party providers' own platforms (payments, e-mail, hosting) — please report those to the provider directly.
Security reports: support@apprump.com — subject Security report.