How to report
Email support@synq.build with “Security report” in the subject. Please include:
- what is affected: a host, an endpoint, a page or a package;
- the steps to reproduce it, and what you expected instead;
- what an attacker could do with it;
- whether and how you would like to be credited.
Please don’t put details of an unfixed vulnerability anywhere public.
What is in scope
- synq.build and every host under it, including each brand’s issuer;
- Synq’s management API, account API and hosted sign-in pages;
- Synq’s published SDKs, once they are published.
Out of scope: findings without a practical impact (such as a missing header on its own), denial-of-service and volume testing, social engineering of our staff, and flaws in services Synq uses that we don’t control.
What we ask of you
- Use only accounts and data you own or have permission to use.
- Never view, change or keep other people’s data beyond what proves the issue, and stop if you reach it.
- Don’t degrade the service for anyone else.
- Give us a reasonable time to fix the issue before you disclose it; we aim for 90 days at most.
What we commit to
- We reply to every report and keep you updated until it is resolved.
- We credit you publicly when it is fixed, if you want us to.
- We won’t take legal action against research done in good faith that follows this policy.