Security & Vulnerability Disclosure
Last Updated: June 28, 2026
Phossil holds family photos and the stories that go with them. If you believe you’ve found a security issue, we want to hear about it first.
How to Report
Email [email protected] with:
- A description of the issue and its impact
- Steps to reproduce, with the URL or endpoint affected
- Any proof-of-concept code or screenshots
- Your name (if you’d like credit) or “anonymous”
We acknowledge reports within 5 business days and aim to fix high-severity issues within 30 days.
In Scope
phossil.aiand any subdomain we operate- Authentication and session management (Passport.js, magic-link, password reset)
- Authorization across collections, families, and roles (owner, editor, viewer)
- Photo upload, storage, and access controls (including R2 signed URLs)
- Face grouping: the on-device no-upload guarantee (no biometric data is stored on our servers)
- Credit ledger and Stripe payment flow (refunds, idempotency, double-spend)
- Injection vulnerabilities (XSS, SSRF, RCE, SQLi)
- CSRF on state-changing endpoints
- Sensitive data exposure (account email, photos, billing data)
Out of Scope
- Third-party services we don’t operate (Stripe, Cloudflare, R2, Google Cloud, Replicate)
- Rate limiting on public marketing pages
- Missing security headers without demonstrated impact
- Self-XSS or social engineering of staff or customers
- Denial of service, spam, or volumetric attacks
- Reports from automated scanners with no demonstrated impact
- AI output quality issues (those are bug reports, not security)
Rules of Engagement
- Don’t access, modify, or delete data that isn’t yours. A proof-of-concept is enough.
- Don’t test against other people’s collections, photos, or face data.
- Don’t perform DoS testing or run automated scanners that generate excessive traffic.
- Don’t disclose the issue publicly until we’ve had a chance to fix it, or 90 days have passed, whichever comes first.
Safe Harbor
We won’t pursue legal action against researchers who make a good-faith effort to comply with this policy, stop testing once a vulnerability is identified, and report findings through the channel above. We treat compliant research as authorized under the Computer Fraud and Abuse Act and similar laws.
Bounty & Credit
We don’t currently offer a paid bounty. We do credit researchers who report valid issues (with their permission) once the fix ships.
Machine-Readable
Our security.txt file is at /.well-known/security.txt per RFC 9116.