VeloLog — Security Disclosure Policy

Version 1.0 · Drafted [Date]

If you believe you've found a security vulnerability in VeloLog, we want to hear about it. This page explains how to report responsibly and what you can expect from us in return.


How to report

Email security@velolog.io with as much detail as you can share:

If the vulnerability is sensitive (data exposure, account takeover, authentication bypass), encrypt the report with our PGP key:

`` [PGP key fingerprint and public key block to be inserted here once generated] ``


What you can expect from us


Rules for safe testing

To stay within the safe-harbour described below, please:


Safe harbour

We commit not to pursue legal action against anyone who:

This safe harbour applies to civil claims VeloLog could otherwise bring under the Computer Misuse Act 1990 (UK), equivalent national laws, contract law, or otherwise. It does not override criminal law in jurisdictions where unauthorised access is itself a crime regardless of intent — please check your local law.

If a third party (a User, a regulator, law enforcement) brings a claim against you in connection with your report, we will, where lawful, do what we reasonably can to support you, including providing documentation that you acted under this Policy.


What's in scope

In scopeOut of scope
velolog.io and all subdomainsThird-party services we integrate with (Stripe, Strava, etc.) — please report to them
Our mobile and desktop appsIssues that require physical access to a User's device
Our API endpointsIssues already publicly known or in our security advisories
Authentication, authorisation, encryptionDoS attacks via brute force or volume
Personal-data handlingIssues that depend on outdated or unsupported browsers

Specific things we want to hear about


What's less interesting

We'd rather not receive reports on:

These aren't unwelcome, just lower priority.


How fast we fix

We try to resolve based on impact:

SeverityTarget time to fix
Critical (account takeover, PII dump, RCE)24 hours
High (privilege escalation, data exposure)7 days
Medium (IDOR limited to small data, XSS)30 days
Low (cookie hardening, headers)Next scheduled release

We will tell you when a fix is deployed and invite you to verify.


Past advisories

Resolved vulnerabilities are published at velolog.io/legal/security-advisories with reporter attribution (consent permitting).


Contact

security@velolog.io for vulnerability reports.

For general security questions: support@velolog.io.

For privacy-related issues (data exposure, breach response): dpo@velolog.io.