Security and responsible disclosure
Found a security problem in Put It Online? Thank you. Please tell us privately so we can fix it before anyone gets hurt.
How to report
Email security@putit.online with what you found, the steps to reproduce it, and what an attacker could do with it. Screenshots or a short proof of concept help. A person reads every report; we aim to reply within 3 business days and to keep you updated until it's fixed.
Our security.txt lists the same contact. To report abusive content (phishing, malware, illegal files) rather than a vulnerability, use the report form or abuse@putit.online.
In scope
putit.online: the website, accounts, dashboard, billing pages, REST API (/api/v1), MCP server (/mcp) and OAuth endpoints (/oauth/*).files.putit.online: where uploaded files are served.- Our published packages and repositories, such as putit-mcp.
Out of scope
- Content people upload to their own links (report it as abuse instead).
- Denial of service, load testing, spam, or social engineering of our staff or users.
- Findings from automated scanners without a demonstrated impact, missing best-practice headers with no exploit, and self-XSS.
- Third-party services we use (Cloudflare, Stripe, email providers): report those to the vendor.
Please
- Only test against accounts and links you own, or have explicit permission to use.
- Don't access, change or delete other people's data. If you reach any by accident, stop, don't keep it, and tell us.
- Don't degrade the service for others, and don't upload malware or illegal content to test our scanning.
- Give us reasonable time to fix the problem before you share details publicly (we suggest 90 days, or sooner once it's fixed).
Safe harbor
If you make a good-faith effort to follow this policy, we consider your research authorised, won't pursue legal action or ask anyone else to, and will work with you to understand and fix the issue quickly. If a third party brings action against you for activity that followed this policy, we'll make it known that your work was authorised. We don't run a paid bug bounty yet, but we're happy to credit you for a valid report.