Home/Security/Responsible disclosure
Responsible disclosure

Found a bug? Tell us.

Linebook holds sensitive things — client health forms, waivers, photos and studios' money. We'd much rather hear about a security flaw from you than read about it later. If you're a security researcher acting in good faith, this page is our standing invitation and our promise not to come after you for it.

01How to report

Email security@linebook.ink. A good report includes:

  • What the issue is, and the security impact you think it has.
  • Clear steps to reproduce it — a proof-of-concept, request, or short screen recording.
  • The affected URL or area, and roughly when you tested.
  • How we can reach you for follow-up (and whether you'd like credit).

Our machine-readable contact info lives at /.well-known/security.txt (RFC 9116).

02What's in scope

  • linebook.ink and its subdomains — the marketing site, the studio console (studio.linebook.ink), and studios' public booking sites (<studio>.linebook.ink).
  • The booking API and the embeddable booking widget.
  • Authentication, session handling, access control between studios and roles, and the encryption of client intake.

03What's out of scope

These aren't things we can act on, so please don't spend your time (or ours) on them:

  • Findings against our providers rather than us — Stripe, Vercel, Neon, Resend, Cloudflare, Fastmail. Report those to them.
  • Denial of service, volumetric or brute-force testing, and anything that degrades the service for real studios or their clients.
  • Social engineering, phishing, or physical attacks against our team, our studios or their clients.
  • Automated-scanner output with no demonstrated impact, and best-practice notes with no concrete vulnerability (a missing header, a cookie flag, an email SPF nitpick, version disclosure, self-XSS).
  • The operator back office — it isn't reachable from the public internet, so it isn't a valid target.

04Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised. We won't pursue or support legal action against you, and we'll work with you to understand and fix the issue. In return, please:

  • Only test against your own account and data — never access, modify or store another studio's or client's information. If you stumble onto someone else's data, stop and tell us.
  • Don't run attacks that degrade the service, and don't exfiltrate more than the minimum needed to prove the issue.
  • Give us a reasonable chance to fix it before you disclose it publicly — we'll keep you posted, and we're not slow.

05What to expect from us

  • We aim to acknowledge your report within 3 business days.
  • We'll confirm whether we can reproduce it, and keep you updated as we work through it.
  • We'll let you know when it's fixed — and we're glad to coordinate timing if you plan to write it up.

06Saying thank you

We're a small, bootstrapped team, so we don't run a fixed-price bounty. What we do promise is a genuine thank-you: public credit here if you'd like it, and — at our discretion, for a genuinely impactful, novel and verifiable finding — a token of appreciation, which may be swag, a gift card, or a small bounty. We decide case by case, weighing the real-world risk you helped us close. No fixed amounts, no obligations — but we don't forget a good turn.

This policy may change as Linebook grows. Questions about it? security@linebook.ink. See also our Security overview and Privacy Policy.