Security
We take the security of cabano and the people who use it seriously. If you believe you have found a security vulnerability in cabano, please tell us so we can fix it.
How to report
Email support@cabano.app with “Security” in the subject. Please include:
- a description of the vulnerability and what an attacker could do with it;
- the steps to reproduce it, or a proof of concept;
- the affected URLs, products, or features; and
- how we can reach you with questions.
Don’t include other people’s personal data, passwords, or secrets in your report.
Scope
- the cabano website and its API at cabano.app;
- cabano in ChatGPT, including the cabano.app/mcp endpoint; and
- the cabano app for Slack.
Out of scope:
- apps that people build and publish with cabano, unless the issue comes from code or infrastructure that cabano provides;
- services we rely on, such as Slack, OpenAI, Anthropic, Apple, GitHub, and Amazon Web Services; please report those to the provider;
- denial-of-service or high-volume automated testing;
- social engineering, phishing, or physical attacks; and
- scanner output or missing best-practice settings without a demonstrated security impact.
Guidelines
- Test only with accounts you own or have permission to use.
- Don’t access, change, or delete other people’s data. If you come across it, stop and tell us.
- Don’t degrade the service for others or spend other people’s credits.
- Give us reasonable time to fix the issue before you disclose it publicly.
What to expect
We will acknowledge your report within 3 business days, keep you updated while we investigate, and tell you when the issue is fixed. With your permission, we’re happy to credit you once it is resolved. We don’t currently offer a paid bug bounty.
Safe harbor
If you make a good-faith effort to follow this policy, we will consider your research authorized, we will not pursue legal action against you for it, and we will work with you to understand and resolve the issue quickly.