Security & Vulnerability Disclosure
Chathub App · chathubapp.com · Last updated 2026-07-21
We take security seriously. This page describes how to report security issues responsibly.
Report a Vulnerability
If you believe you have found a security vulnerability in Chathub App, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.
Please email your findings to: security@chathubapp.com
A machine-readable disclosure file is available at /.well-known/security.txt (RFC 9116).
Scope
The following are in scope for this program:
- chathubapp.com — web application and API endpoints
-
Chathub Android app
(
com.strangers.chat_developers.strangerschatapp) - Firebase Cloud Functions serving Chathub users
The following are out of scope:
- Denial of service attacks
- Social engineering attacks against Chathub staff
- Physical security
- Attacks requiring physical access to a user's device
Safe Harbor
We support safe harbor for security researchers who:
- Make a good-faith effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing
- Only interact with accounts they own or have explicit permission from the account owner to test
- Refrain from publicly disclosing vulnerabilities before we have had a reasonable amount of time to address them (we aim for 90 days)
- Report the vulnerability to us before any disclosure
We will not pursue legal action against researchers who act in good faith within the above guidelines.
What to Include in Your Report
- A description of the vulnerability and its potential impact
- Step-by-step reproduction instructions
- Any supporting material (screenshots, PoC code)
- Your contact information for follow-up questions
Our Response Commitment
- Acknowledgement
- within 3 business days of receiving your report
- Status update
- within 10 business days with our assessment
- Resolution target
- within 90 days for confirmed critical or high vulnerabilities
We do not currently offer a monetary bug bounty. We will publicly acknowledge researchers who report valid vulnerabilities (with their permission).
Rules of engagement
- Do not access or modify other users' data.
- Do not perform actions that degrade service availability (e.g., DDoS).
- We will acknowledge receipt and prioritize fixes based on severity.