Security & vulnerability disclosure
Threadmaker (CT Core) welcomes reports from security
researchers acting in good faith. This page is our vulnerability disclosure
policy; the machine-readable version lives at
/.well-known/security.txt
(RFC 9116).
How to report
Email security@threadmaker.dev with enough detail to reproduce the issue: the affected URL or component, the steps, and the impact you believe it has. Please give us a reasonable opportunity to fix an issue before disclosing it publicly. Do not access, modify, or exfiltrate data that is not your own — a minimal proof of concept is enough.
Scope
In scope: threadmaker.dev and its sub-domains, the
Threadmaker Slack app, and the Threadmaker Jira (Forge) app.
Out of scope: the Slack, Atlassian, and Cloudflare platforms themselves — report those to the relevant platform's own security team. Also out of scope: volumetric denial-of-service, social engineering of our staff or customers, physical attacks, and automated-scanner output without a demonstrated, reproducible impact.
Safe harbour
We will not pursue or support legal action against anyone who reports a vulnerability in good faith, follows this policy, and avoids privacy violations, data destruction, and service degradation. If in doubt about whether an action is authorised, ask us first at security@threadmaker.dev.
What you can expect from us
- We aim to acknowledge your report promptly.
- We will keep you informed as we investigate and remediate.
- We are happy to credit you once a fix is released, if you would like that.
Threadmaker does not currently operate a paid bug-bounty program; reports are handled on the good-faith basis described above. There is no PGP key at this time — plain email to the address above reaches our security team.