Vulnerability disclosure policy
Last updated Oct 5, 2026
This policy awaits legal review. We follow it today, and the reviewed version may change its wording.
If you have found a security vulnerability in DeployYourCode, we want to hear about it. This page says how to report it, what we will do, and what we ask of you in return.
Abuse by an app we host — phishing, malware, copyright — is not a vulnerability: report it here. What we have in place today is on the security page.
1. How to report
Email security@deployyourcode.com with:
- what you found, and where;
- the steps to reproduce it;
- what someone could do with it;
- whether you would like to be credited, and under what name.
Do not include a working password, key or token you came across. Tell us it exists and where, and we will rotate it.
Please report through this address only — not the abuse form, our support address or social media — so the report reaches the right person and stays private.
2. What to expect
- We acknowledge your report within five business days and tell you whether we can reproduce it.
- We keep you informed while we fix it, and tell you when it is fixed.
- We ask you to give us 90 days from your report before disclosing it publicly — less if the fix is out sooner — and to agree the date with us.
- We do not run a paid bug bounty yet.
3. In scope
- deployyourcode.com and everything under it: the dashboard, sign-in, the public API and the website.
- The separation between customers. If your own account can reach another organization's data, apps, builds, databases or secrets, that is the most important thing you can tell us.
- How the platform builds, deploys and runs apps — tested with apps and repositories you own.
4. Out of scope
- Apps our customers host, on deployyourcode.app, fly.dev or their own domains. A flaw in one is its owner's to fix; to report abuse by one, use the abuse page. Anything that lets one customer's app reach another's is in scope.
- Our providers' own systems — Fly.io, Cloudflare, Stripe, GitHub, Supabase and the others on our subprocessor list. Report those to the provider.
- Denial of service, load testing and spam.
- Social engineering of our staff or customers, and physical attacks.
- Findings from automated scanners with no demonstrated impact, missing headers or cookie flags with no working exploit, self-XSS, and clickjacking on pages with no sensitive action.
5. Testing in good faith
- Use only accounts, organizations and repositories you created. Never access, change or delete another customer's data; if you reach any, stop, keep no copy, and tell us.
- Do not degrade the service for anyone else: no denial of service, no high-volume automated scanning.
- Do not use what you find beyond what is needed to show it, and do not move from it to other systems.
- Do not run builds or apps meant to harm the platform beyond proving the issue — no mining, no persistence.
- Keep the details confidential until it is fixed or the disclosure date we agree.
- Follow the law.
6. Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue or support legal action against you for it, including claims under computer misuse or anti-circumvention laws, and for that research we waive the parts of our terms of service that would otherwise forbid it.
If someone else takes legal action against you for research you carried out under this policy, we will make it known that you acted in line with it.
If you are not sure whether something is allowed, ask us at security@deployyourcode.com before you do it.