Thank you for helping us keep Cache secure. We take the security of our application and our users' data seriously.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| 0.x.0 | ✅ |
Please report vulnerabilities directly to notices@cachd.app. Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested mitigations
Do not disclose the vulnerability publicly until it has been addressed.
- We will acknowledge receipt within 48 hours.
- We will provide an estimated timeline for a fix.
- We will notify you when the issue is resolved.
- We will publicly acknowledge your contribution (unless you prefer to remain anonymous).
Cache is a web application at cachd.app and includes:
- The main Next.js application
- The browser extension (Chrome)
- Public API endpoints
- Third-party services we integrate with (Instagram, TikTok, YouTube, etc.)
- Infrastructure vulnerabilities in our hosting providers
- Social engineering attacks
We believe in coordinated disclosure. We ask that you:
- Report vulnerabilities privately.
- Give us reasonable time to respond and fix the issue.
- Avoid accessing or modifying user data without permission.
- Act in good faith to avoid privacy violations and data destruction.