If you discover a security vulnerability in Blivz, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, email us at: security@blivz.com
Please include:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fixes (if applicable)
We will acknowledge your report within 48 hours and aim to provide a fix or mitigation plan within 7 days.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | Best effort |
The following are in scope for security reports:
- The Blivz web application
- The AWS Lambda enrichment backend
- The Cloudflare CSV import worker
- Authentication and authorization flows
- Data encryption and API key storage
- Any publicly deployed infrastructure
We kindly ask that you:
- Give us reasonable time to fix the issue before public disclosure
- Do not access or modify other users' data
- Do not perform denial-of-service attacks
- Act in good faith to avoid privacy violations
We appreciate your help in keeping Blivz and its users safe.