Skip to content

Security: reduce/blivz

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Blivz, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, email us at: security@blivz.com

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes (if applicable)

We will acknowledge your report within 48 hours and aim to provide a fix or mitigation plan within 7 days.

Supported Versions

Version Supported
Latest release Yes
Older releases Best effort

Scope

The following are in scope for security reports:

  • The Blivz web application
  • The AWS Lambda enrichment backend
  • The Cloudflare CSV import worker
  • Authentication and authorization flows
  • Data encryption and API key storage
  • Any publicly deployed infrastructure

Responsible Disclosure

We kindly ask that you:

  1. Give us reasonable time to fix the issue before public disclosure
  2. Do not access or modify other users' data
  3. Do not perform denial-of-service attacks
  4. Act in good faith to avoid privacy violations

We appreciate your help in keeping Blivz and its users safe.

There aren't any published security advisories