Security & vulnerability disclosure

Threadmaker (CT Core) welcomes reports from security researchers acting in good faith. This page is our vulnerability disclosure policy; the machine-readable version lives at /.well-known/security.txt (RFC 9116).

How to report

Email security@threadmaker.dev with enough detail to reproduce the issue: the affected URL or component, the steps, and the impact you believe it has. Please give us a reasonable opportunity to fix an issue before disclosing it publicly. Do not access, modify, or exfiltrate data that is not your own — a minimal proof of concept is enough.

Scope

In scope: threadmaker.dev and its sub-domains, the Threadmaker Slack app, and the Threadmaker Jira (Forge) app.

Out of scope: the Slack, Atlassian, and Cloudflare platforms themselves — report those to the relevant platform's own security team. Also out of scope: volumetric denial-of-service, social engineering of our staff or customers, physical attacks, and automated-scanner output without a demonstrated, reproducible impact.

Safe harbour

We will not pursue or support legal action against anyone who reports a vulnerability in good faith, follows this policy, and avoids privacy violations, data destruction, and service degradation. If in doubt about whether an action is authorised, ask us first at security@threadmaker.dev.

What you can expect from us

Threadmaker does not currently operate a paid bug-bounty program; reports are handled on the good-faith basis described above. There is no PGP key at this time — plain email to the address above reaches our security team.