Security & Vulnerability Disclosure

Last Updated: June 28, 2026

Phossil holds family photos and the stories that go with them. If you believe you’ve found a security issue, we want to hear about it first.

How to Report

Email [email protected] with:

We acknowledge reports within 5 business days and aim to fix high-severity issues within 30 days.

In Scope

Out of Scope

Rules of Engagement

Safe Harbor

We won’t pursue legal action against researchers who make a good-faith effort to comply with this policy, stop testing once a vulnerability is identified, and report findings through the channel above. We treat compliant research as authorized under the Computer Fraud and Abuse Act and similar laws.

Bounty & Credit

We don’t currently offer a paid bounty. We do credit researchers who report valid issues (with their permission) once the fix ships.

Machine-Readable

Our security.txt file is at /.well-known/security.txt per RFC 9116.