Skip to content
Responsible disclosure

Security at CopyForge AI

If you believe you found a vulnerability in CopyForge AI, report it privately through the form below. We value clear, good-faith research and will not ask you to hide a real risk indefinitely.

Private intake

Reports are stored in our restricted contact system before the form confirms receipt.

Response targets

We aim to acknowledge reports within 3 business days and provide a status update within 10.

Useful detail

Include the affected URL, exact reproduction steps, practical impact, and a minimal proof.

Scope

This policy covers the CopyForge AI web application and API hosted at copy-forge-ai.com. Third-party services such as Supabase, Vercel, Resend, Gumroad, and model providers are governed by their own disclosure programs unless the issue is caused by our integration.

High-value reports include broken authentication or authorization, cross-account data access, injection, request forgery, sensitive-data exposure, payment entitlement bypass, and a reproducible security control failure.

Testing rules

  • Use only accounts and data you own or have explicit permission to test.
  • Stop immediately if you encounter another person's data, and report what you saw without copying it.
  • Use the minimum proof needed. Do not persist access, install malware, or alter or delete data.
  • Do not perform denial-of-service, load testing, spam, social engineering, credential stuffing, or physical attacks.
  • Do not test third-party payment flows with fraudulent transactions or target provider infrastructure.
  • Do not publicly disclose an unremediated issue before giving us a reasonable opportunity to investigate and fix it.

Good-faith safe harbor

When research follows this policy, is intended to improve security, avoids privacy harm and service disruption, and complies with applicable law, we will treat it as authorized security research and will not initiate legal action based solely on that work. If a third party starts legal action, we will make our authorization under this policy known. This statement does not authorize activity against third-party systems or waive rights belonging to anyone else.

What happens after a report

  1. We confirm that the report was stored and review whether it is reproducible and in scope.
  2. We may contact you for a minimal additional proof or environment detail.
  3. We prioritize remediation by exploitability and impact, then verify the fix.
  4. We coordinate disclosure timing in good faith. We do not offer a paid bounty program at this time.

Submit a security report

Do not include passwords, session cookies, API keys, full payment details, or personal data. The email address you provide is used only to follow up on this report and is handled under our Privacy Policy.

0/4000 characters