Security
Report a vulnerability
Found a security problem? Thank you! Please write to us confidentially at security@tellersonne.app, subject "Security Tellersonne".
What to include
Name the affected part (app, API, admin panel or recipe pages), the steps to reproduce and the possible impact. Please do not report security problems publicly, for example in a comment or on GitHub.
Ground rules while testing
- Do not access, change or delete real user data.
- No load, spam or denial-of-service tests.
- Publish details only once we have fixed the problem.
When you will hear from us
We confirm receipt within 3 business days, send an assessment within 10 business days and let you know as soon as the problem is fixed. On request we credit you in the release notes.
Which versions we support
API, admin panel and recipe pages in their current state, the app in the current store version and the current beta. Older app versions ask you to update.
Our reporting channels are also machine-readable in security.txt (RFC 9116).