Security
Security and vulnerability disclosure
If you have found a weakness in VibedSites.ai, tell us and we will work it with you. Good-faith research is welcome here.
Effective 10 September 2026 · Last updated 10 September 2026
How to report
Email admin@VibedSites.ai with the subject line starting "Security". Include the affected page or request, the steps to reproduce, what an attacker could achieve, and anything we need to see it ourselves, such as a short video or a request sample. Please do not post the details publicly before we have had a chance to fix them.
What we promise
- We acknowledge reports within 3 business days.
- We give you an initial assessment, including whether we consider it in scope, within 7 business days.
- We keep you updated while we fix it, and we tell you when the fix is live.
- We will not pursue legal action over good-faith research that follows this policy.
- We credit you by name or handle if you would like that, once the fix has shipped.
In scope
- vibedsites.ai and www.vibedsites.ai, including the account, submission, moderation and admin surfaces.
- Authentication and authorization flaws, including any way to read or change data belonging to another account.
- Injection, cross-site scripting, request forgery, server-side request forgery, and insecure file handling.
- Exposure of secrets, internal endpoints or private storage objects.
Out of scope
- Automated scanner output with no demonstrated impact.
- Denial of service, volumetric or brute-force testing, and anything that degrades the service for other people.
- Social engineering of our team, our users or our vendors, and physical attacks.
- Reports about sites that are merely listed here. Those belong on the abuse report page, because we do not operate them.
- Missing hardening headers or best practices with no exploitable consequence.
Rules for testing
- Use your own accounts and your own test data.
- Do not access, modify, download or retain anyone else's personal data. If you encounter it, stop and tell us.
- Do not run destructive tests, and do not keep access once you have proven the issue.
- Stay within the domains listed above. Third-party providers have their own disclosure programmes.
How we handle incidents
Taout, Inc. triages every report, reproduces it, assigns a severity, and fixes critical and high issues first. We record what happened, what we changed and when, revoke or rotate anything that may have been exposed, and notify affected people and the relevant authorities where the law requires it. Privileged actions on the platform are authorized on the server and recorded, so we can reconstruct what took place.
Related pages
Questions about any of this? Get in touch.