We take security seriously. If you discover a security vulnerability, please do not open a public issue.
نحن نأخذ الأمان على محمل الجد. إذا اكتشفت ثغرة أمنية، من فضلك لا تنشئ Issue عام.
- Privately: Go to Security Advisories
- Email: (coming soon)
- Telegram: (coming soon)
- Type of vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and provide a timeline for the fix within 5 business days.
سنؤكد الاستلام خلال 48 ساعة ونقدم جدول زمني للإصلاح خلال 5 أيام عمل.
The following are in scope:
- Backend API (
/stroapp/endpoints) - Authentication and authorization
- Data privacy and access control
- Payment processing
- User data exposure
- Theoretical vulnerabilities without proof of concept
- Rate limiting bypass (we track this separately)
- SSL/TLS configuration (handled by infrastructure)
- Dependency CVEs without exploit context