Security Disclosure Policy

Reporting Security Issues

If you discover a vulnerability in Aptli, please report it promptly to security@aptli.io.

Include the following information when possible:

  • A clear description of the issue.
  • Steps to reproduce the problem.
  • Affected URL, deployment, or feature.
  • Any screenshots, logs, or proof-of-concept details.

Response and Acknowledgement

We aim to acknowledge every valid report within 72 hours and to keep you informed about our progress.

What We Will Do

  • Review reports promptly and investigate the issue.
  • Confirm whether the report is valid.
  • Provide remediation guidance and deploy fixes as needed.
  • Keep communications confidential and respect your disclosure.

Safe Harbor

When you act in good faith and follow the reporting process, we will not pursue legal action against you for the security research activity described in your report.

Exclusions

Please do not submit:

  • Requests for payment, bounty, or other compensation.
  • Personal data unrelated to the vulnerability.
  • Site abuse reports outside of security issues (such as spam or customer support requests).
  • Any activity that violates applicable law.

Additional Information

Our security disclosure page is available at /security-disclosure and our security contact address is security@aptli.io.