# Varsity Stack — security contact and disclosure policy # https://varsitystack.com/.well-known/security.txt # # Varsity Stack is a small team. We do not run a paid bug bounty and we do not # want a researcher to discover that after doing the work, so it is stated here # rather than in a reply. We do acknowledge every report, we do fix what is # real, and we credit researchers who ask to be credited. Contact: mailto:support@varsitystack.com Contact: https://trust.varsitystack.com/ Expires: 2027-08-13T00:00:00Z Preferred-Languages: en Canonical: https://varsitystack.com/.well-known/security.txt Canonical: https://trust.varsitystack.com/.well-known/security.txt Policy: https://trust.varsitystack.com/ # What we ask # # Give us a way to reproduce it, and give us time to fix it before publishing. # Do not access, modify or retain data belonging to anyone other than yourself, # and do not run automated scans that degrade the service for athletes or the # staff using the team dashboard. Testing that stays inside those lines will not # draw a legal complaint from us. # # In scope: varsitystack.com, trust.varsitystack.com, app.varsitystack.com, # api.varsitystack.com, and the mobile apps # (iOS com.varsitystack.app, Android com.varsitystack.mobile) # Out of scope: our infrastructure providers' own systems. Report those to the # provider — Google Cloud, Supabase, Cloudflare and OpenAI each run # their own disclosure programme. # # We aim to acknowledge a report within 3 business days.