Skip to content

Security: rortan134/cache-app

Security

SECURITY.md

Security Policy

Thank you for helping us keep Cache secure. We take the security of our application and our users' data seriously.

Supported Versions

Version Supported
1.x
0.x.0

Reporting a Vulnerability

Please report vulnerabilities directly to notices@cachd.app. Include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested mitigations

Do not disclose the vulnerability publicly until it has been addressed.

What to expect

  • We will acknowledge receipt within 48 hours.
  • We will provide an estimated timeline for a fix.
  • We will notify you when the issue is resolved.
  • We will publicly acknowledge your contribution (unless you prefer to remain anonymous).

Scope

Cache is a web application at cachd.app and includes:

  • The main Next.js application
  • The browser extension (Chrome)
  • Public API endpoints

Out of Scope

  • Third-party services we integrate with (Instagram, TikTok, YouTube, etc.)
  • Infrastructure vulnerabilities in our hosting providers
  • Social engineering attacks

Disclosure Policy

We believe in coordinated disclosure. We ask that you:

  1. Report vulnerabilities privately.
  2. Give us reasonable time to respond and fix the issue.
  3. Avoid accessing or modifying user data without permission.
  4. Act in good faith to avoid privacy violations and data destruction.

There aren't any published security advisories