Security and vulnerability disclosure

If you have found a security issue in Vantage, we want to hear about it, and we would rather hear about it from you than from an incident. This page sets out how to report one and what happens next.

Reporting

Email team@vantageos.tech with the subject line Security report. Include how to reproduce the issue and what it lets an attacker do. If you need to send anything sensitive, say so and we will arrange an encrypted channel.

What happens next

1

Report it

Email team@vantageos.tech with what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps. Please do not open a public issue.

2

We acknowledge

You will get a human reply within three business days confirming we have the report and whether we can reproduce it.

3

We assess and fix

We triage by real-world impact. Anything that exposes customer data or allows access to another workspace is treated as urgent and worked on immediately. Lower-severity issues are scheduled and you will be told roughly when to expect a fix.

4

We confirm and credit

You will be told when the fix ships. If you would like to be credited by name, say so in your report and we will name you here once the issue is resolved.

In scope

  • app.vantageos.tech and api.vantageos.tech
  • vantageos.tech and its subpages
  • The Vantage plugin for Figma

Out of scope

  • Findings from automated scanners without a demonstrated impact
  • Missing hardening headers or TLS configuration with no exploitable consequence
  • Denial of service, volumetric testing, or anything that degrades the service for other people
  • Social engineering of our team, customers, or vendors
  • Reports about third-party services we depend on — please report those to the vendor

Testing safely

Please test only against data you own. Use your own workspace and your own account, do not access, modify or retain anyone else's data, and stop as soon as you have confirmed a finding. If you follow this and report in good faith, we will not pursue or support legal action against you for your research.

We do not currently run a paid bug bounty, and we are not accredited to SOC 2 or ISO 27001. We would rather say so plainly than imply otherwise.

For how we handle personal data, see our privacy policy. For what the Figma plugin reads and stores, see the plugin documentation.