/ RESPONSIBLE DISCLOSURE

Reporting a security issue

Crosshire is solo-built and not for profit. There's no bug bounty and no payout — but reports are read by a human, taken seriously, and credited if you want the credit.

/ How to report

Email rentals@wearestepchild.com. Include enough detail to reproduce the issue — affected URL or endpoint, the steps you took, and what you observed. Proof-of-concept code or a screen recording helps.

Please report privately and give us a chance to fix it before disclosing publicly. We won't pursue legal action against anyone who reports in good faith, stays within the scope below, and doesn't access, modify, or retain other members' data.

In scope

  • /crosshire.app and its subdomains
  • /The member dashboard, request/offer flows, and invite handling
  • /Authentication, session handling, and cross-member data access

Out of scope

  • /Denial of service, volumetric, or brute-force testing
  • /Social engineering of members or staff, and physical access attempts
  • /Reports generated solely by automated scanners with no demonstrated impact
  • /Missing hardening headers or TLS configuration with no exploitable impact
  • /Third-party services we don't operate (Supabase, Lovable, email providers)

/ What to expect

acknowledgement within 5 business days

an assessment — whether we consider it a vulnerability, and roughly when we expect to fix it — within 10 business days

a note when it's fixed, and credit on request. this is a one-person project, so timelines are best-effort rather than a contractual SLA.

Machine-readable contact details live at /.well-known/security.txt.